CVE-2026-48482
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 02:54
Description
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
Public references
- https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm
https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm - https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19
https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.