The flaw is in the Form import flow, where GLPI processes an illustration or scene identifier to determine where an imported file is stored. An attacker-controlled identifier can escape the intended custom-asset directory through path traversal, allowing the imported file to be written to an executable server location.
The high-level attack flow established by the sources is:
- An account with form administrator privileges accesses
Form import.
- The imported data contains a crafted illustration or scene identifier.
- The file is moved outside the intended custom-asset directory and may be placed in an executable location.
- A malicious script can then be invoked remotely.
The fix in FormSerializer::prepareIllustrationDataForImport adds validation that restricts illustration keys to the pattern [a-zA-Z0-9._-]+. IllustrationManager::saveCustomIllustration and IllustrationManager::saveCustomScene also verify that the resolved destination remains inside the corresponding directory before calling rename. The public sources do not fully establish the server process privileges or web-server configuration, so post-exploitation reach depends on the deployment environment.