CVE-2024-27756: GLPI-Project GLPI

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

Affected products

Published 2024-03-15. Last modified 2026-06-17.