Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-27914 | Kitploit
Tools/GitHubGitHub/shellkraft/cve-2024-27914
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubshellkraft/cve-2024-27914

CVE-2024-27914

View Repository
2 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-27914: Reflected XSS in debug mode of GLPI


An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar.


  • Package - GLPI (https://github.com/glpi-project/glpi)
  • Affected Version - >= 10.0.8
  • Patched Version - 10.0.13

PoC - http://<host>/glpi/front/search.php?globalsearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3E


Reference:

  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27914
  • https://nvd.nist.gov/vuln/detail/CVE-2024-27914
Download Tool