{"id":"CVE-2026-48482","published":"2026-09-25T19:16:55.180","lastModified":"2026-09-30T01:16:37.383","description":"GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19","tags":[]},{"url":"https://github.com/glpi-project/glpi/releases/tag/11.0.8","tags":[]},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm","tags":[]}],"exploitRefs":[{"url":"https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19","tags":[]},{"url":"https://github.com/glpi-project/glpi/releases/tag/11.0.8","tags":[]},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm","tags":[]}],"hasPoc":true,"ai":null}