Glpi · Glpi · CVE-2023-28636
**Name of the Vulnerable Software and Affected Versions**
GLPI versions 0.60 through 9.5.12
GLPI versions 10.0.0 through 10.0.6
**Description**
The issue is related to insufficient cleaning of user data when processing external links, allowing a user to inject and execute arbitrary HTML code and scripts in the user's browser within the context of the vulnerable website. This can enable a remote attacker to steal potentially confidential information, modify the appearance of web pages, and perform phishing and drive-by download attacks.
**Recommendations**
For GLPI versions 0.60 through 9.5.12, update to version 9.5.13 to resolve the issue.
For GLPI versions 10.0.0 through 10.0.6, update to version 10.0.7 to resolve the issue.