CVE-2024-27756: GLPI-Project GLPI
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
Affected products
- GLPI-Project GLPI: up to and including 10.0.12
Published 2024-03-15. Last modified 2026-06-17.