Impact
GLPI is an asset and IT management platform that suffered a Server‑Side Template Injection vulnerability in templating logic. Based on the description, it is inferred that an authenticated administrator can craft input that is compiled twice by the template engine, which allows injection of arbitrary code and effectively bypasses the web application’s input filtering. This injection aligns with the Common Weakness Enumeration categories for code injection and template injection.
Affected Systems
The vulnerability exists in GLPI versions between 11.0.0 and just before 11.0.6, inclusive. Users running any of those releases are at risk until the upstream developers push the fix delivered in the 11.0.6 release. Based on the description, it is inferred that an attacker must authenticate with administrative rights to trigger the template injection, limiting impact to systems where the GLPI installation is accessible to administrators.
Risk and Exploitability
The flaw received a CVSS score of 9.1, indicating a high severity, yet the EPSS probability is now reported as 11%, suggesting that exploitation remains uncommon but not negligible. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating it has not yet been widely abused. Based on the description, it is inferred that an attacker must gain admin credentials or otherwise compromise an administrator’s session for the web‑based exploitation to provide full control of the underlying server.
OpenCVE Enrichment