{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/glpi--11.0.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GLPI (\u003c 11.0.8)","GLPI (\u003c 10.0.26)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","sql-injection","xss","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["GLPI Project"],"content_html":"\u003cp\u003eMultiple critical vulnerabilities have been identified in GLPI versions 11.0.x prior to 11.0.8 and versions prior to 10.0.26. These vulnerabilities, detailed across several GLPI security advisories (GHSAs) and CVEs, include SQL injection (SQLi), cross-site scripting (XSS), and privilege escalation flaws. If exploited, these weaknesses could allow an attacker to gain unauthorized access to sensitive data, tamper with existing information, circumvent established security controls, or escalate their privileges within the GLPI application. The advisory, issued by CERT-FR on July 27, 2026, urges users to apply immediate patches to prevent potential compromise of their GLPI instances. These vulnerabilities pose a significant risk to the integrity and confidentiality of information managed by GLPI.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eVulnerability Discovery\u003c/strong\u003e: An attacker identifies an internet-facing or internally accessible GLPI instance running a vulnerable version (e.g., glpi versions 11.0.x earlier than 11.0.8 or versions earlier than 10.0.26).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMalicious Request Crafting\u003c/strong\u003e: The attacker crafts and sends specially malformed HTTP requests targeting identified vulnerabilities, such as parameters susceptible to SQL injection or input fields allowing cross-site scripting (XSS).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSQL Injection Exploitation\u003c/strong\u003e: If successful, the attacker's crafted input executes unauthorized SQL queries against the GLPI database, leading to unauthorized data retrieval, modification, or deletion, potentially extracting sensitive information or altering application behavior.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eXSS Exploitation\u003c/strong\u003e: Alternatively, successful XSS exploitation injects malicious client-side scripts into web pages served by GLPI. When a legitimate user accesses the affected page, the script executes in their browser, potentially leading to session hijacking, credential theft, or redirection to attacker-controlled sites.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivilege Escalation\u003c/strong\u003e: Utilizing a specific vulnerability, the attacker exploits their existing access to gain higher-level permissions within the GLPI application, or potentially on the underlying operating system.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Integrity Compromise / Policy Bypass\u003c/strong\u003e: With elevated privileges or successful data manipulation via SQLi, the attacker can bypass security policies, compromise the integrity of data stored or managed by GLPI, or achieve full administrative control over the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could lead to severe consequences for organizations utilizing GLPI. Attackers could achieve complete data integrity compromise, leading to unauthorized modification or deletion of critical IT asset management and helpdesk data. The ability to bypass security policies could grant attackers unfettered access to sensitive configurations or user accounts. Privilege escalation allows attackers to gain administrative control, enabling them to disrupt services, exfiltrate confidential information, or deploy further malicious payloads. The scope of impact is potentially high for any organization using affected GLPI versions, as these systems often manage critical operational data and access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all affected GLPI installations immediately by upgrading to GLPI version 11.0.8 or newer, or GLPI version 10.0.26 or newer, as detailed in the GLPI security advisories referenced.\u003c/li\u003e\n\u003cli\u003eReview web server logs for suspicious HTTP requests targeting GLPI endpoints, especially those containing common SQL injection or XSS payloads as indicators of attempted exploitation of CVE-2026-47678, CVE-2026-47679, CVE-2026-52848, CVE-2026-53610, CVE-2026-53625, CVE-2026-53629, CVE-2026-55214, and CVE-2026-57152.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to detect and block common SQL injection and XSS patterns, which can help mitigate exploitation attempts against the vulnerabilities described in this brief.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unusual outbound connections from your GLPI server, which could indicate post-exploitation activity after a successful privilege escalation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T12:39:43Z","date_published":"2026-07-27T12:39:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-multiple-glpi-vulnerabilities/","summary":"Multiple vulnerabilities have been discovered in GLPI, including SQL injection, cross-site scripting (XSS), and privilege escalation, which could allow an attacker to compromise data integrity, bypass security policies, and elevate their privileges within the system.","title":"Multiple Vulnerabilities in GLPI","url":"https://feed.craftedsignal.io/briefs/2026-07-multiple-glpi-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - GLPI (\u003c 11.0.8)","version":"https://jsonfeed.org/version/1.1"}