{"id":"CVE-2021-21313","details":"GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, indeed, at least two parameters _target and id are not properly sanitized. Here are two payloads (due to two different exploitations depending on which parameter you act) to exploit the vulnerability:/ajax/common.tabs.php?_target=javascript:alert(document.cookie)&_itemtype=DisplayPreference&_glpi_tab=DisplayPreference$2&id=258&displaytype=Ticket (Payload triggered if you click on the button). /ajax/common.tabs.php?_target=/front/ticket.form.php&_itemtype=Ticket&_glpi_tab=Ticket$1&id=(){};(function%20(){alert(document.cookie);})();function%20a&#.","aliases":["GHSA-h4hj-mrpg-xfgx"],"modified":"2026-08-07T17:28:02.538900Z","published":"2021-03-03T20:15:12.200Z","references":[{"type":"ADVISORY","url":"https://github.com/glpi-project/glpi/releases/tag/9.5.4"},{"type":"ADVISORY","url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-h4hj-mrpg-xfgx"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/glpi-project/glpi","events":[{"introduced":"0"},{"fixed":"59a0a0b6101fcd54b00bfc6a61d4e707513c08c9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"9.5.4"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*"}}],"versions":["9.5.3","9.5.2","9.5.1","9.5.0","9.5.0-rc2","9.5.0-rc1","9.4.1.1","9.4.1","9.4.0","9.4.0-rc2","9.4.0-rc1","9.4.0-beta","9.3-beta","9.1","9.1-RC2","9.1-RC1","0.90","0.90-RC2","0.90-RC1","0.90-beta2","0.90-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21313.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}