Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-27914 PoC — Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI

Source
Associated Vulnerability
Title:Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI (CVE-2024-27914)
Description:GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar. This issue has been patched in version 10.0.13.
Readme
# CVE-2024-27914: Reflected XSS in debug mode of GLPI 
---
An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar.

---
- Package - GLPI (https://github.com/glpi-project/glpi)
- Affected Version - >= 10.0.8
- Patched Version - 10.0.13
---
PoC - `http://<host>/glpi/front/search.php?globalsearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3E`

---
Reference:

 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27914
 - https://nvd.nist.gov/vuln/detail/CVE-2024-27914
File Snapshot

[4.0K] /data/pocs/6a8c45ceecd365f9be1331d92688a00f2ff16a7c └── [ 621] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →