PoC Index

CVE-2026-23489

CRITICAL 9.1EPSS 0.3%

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
0.30% chance of exploitation in the next 30 days, 22th percentile
Published
2026-03-16

Proof-of-concept exploits (1)

References

Related