
An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar.
PoC - http://<host>/glpi/front/search.php?globalsearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
Reference: