{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-59935","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2025-09-23T14:33:49.505Z","datePublished":"2025-12-16T16:34:46.251Z","dateUpdated":"2025-12-16T17:15:24.435Z"},"containers":{"cna":{"title":"GLPI Vulnerable to Unauthenticated Stored XSS on the Inventory page","problemTypes":[{"descriptions":[{"cweId":"CWE-79","lang":"en","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-j8vv-9f8m-r7jx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-j8vv-9f8m-r7jx"}],"affected":[{"vendor":"glpi-project","product":"glpi","versions":[{"version":">= 10.0.0, < 10.0.21","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2025-12-16T16:34:46.251Z"},"descriptions":[{"lang":"en","value":"GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an unauthenticated user can store an XSS payload through the inventory endpoint. Users should upgrade to 10.0.21 to receive a patch."}],"source":{"advisory":"GHSA-j8vv-9f8m-r7jx","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-12-16T17:15:15.316595Z","id":"CVE-2025-59935","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-12-16T17:15:24.435Z"}}]}}