home.social

#glpiplugins — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #glpiplugins, aggregated by home.social.

  1. Source-Driven Recon: When the Patch Becomes the PoC and what CVE-2026-61797 taught us about Disclosure OPSEC

    The post discusses the discovery and reporting of a time-based blind SQL injection vulnerability (CVE-2026-61797) in the GLPI PDF plugin, followed by a chaotic 47-day disclosure process. Subsequent investigations revealed additional undisclosed vulnerabilities and a shift in vulnerability research dynamics, highlighting the impact of advanced tools like LLMs on software security management.

    labs.itresit.es/2026/09/14/sou