Medium severity6.1NVD Advisory· Published May 26, 2021· Updated Jun 17, 2026
CVE-2021-3486
CVE-2021-3486
Description
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:glpi-project:glpi:9.5.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:glpi-project:glpi:9.5.4:*:*:*:*:*:*:*
- (no CPE)range: <=9.5.4
- GLPi/GLPidescription
Patches
Vulnerability mechanics
References
3- n3k00n3.github.io/blog/09042021/glpi_xss.htmlnvdExploitThird Party Advisory
- github.com/Kitsun3Sec/exploits/tree/master/cms/GLPI/GLPI-stored-XSSnvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.