CVE-2026-23489
CRITICALFields GLPI plugin vulnerable to RCE in dropdown generation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-23489. PoCs published by eorll-lgtm.
AI-analyzed exploit summary This exploit demonstrates authenticated remote code execution (RCE) in the GLPI 'Fields' plugin <=1.23.2 by injecting PHP code into a custom dropdown field label, which is then executed when the plugin generates a PHP class. The exploit is blind and requires a super-admin session cookie.
Description
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
Exploits (1)
This exploit demonstrates authenticated remote code execution (RCE) in the GLPI 'Fields' plugin <=1.23.2 by injecting PHP code into a custom dropdown field label, which is then executed when the plugin generates a PHP class. The exploit is blind and requires a super-admin session cookie.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H