Impact
The vulnerability exists in the Tag plugin for GLPI 11 prior to version 2.14.4, where tag names are stored without HTML sanitization and later rendered into the Kanban badge markup without escaping. This flaw allows an attacker to inject arbitrary HTML that is executed in the browsers of users viewing the affected Kanban items. The flaw is a classic instance of Stored Cross‑Site Scripting and is linked to CWE‑79. The likely attack vector is an authenticated user with tag‑management create or update rights who can embed malicious payloads in a tag name.
Affected Systems
All installations of the Tag plugin for GLPI 11 that use a version older than 2.14.4 are affected. There are no specific operating system or GLPI core component version requirements beyond the presence of the Tag plugin. The flaw is confined to the Tag plugin’s handling of tag names within the Kanban interface.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, driven by the ability to execute arbitrary client‑side code and the potential for wide‑scale impact across users. Exploitation requires an authenticated user with tag‑management privileges, and once a tag containing a malicious payload is created, all users viewing the relevant Kanban element will be affected. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation, but the absence of exposure does not mitigate the need for immediate remediation.
OpenCVE Enrichment