PT-2019-11558 · Teclib · Glpi
Published
2019-07-15
·
Updated
2019-07-18
·
CVE-2019-1010307
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
GLPI version 9.3.1
Description:
The issue affects the
/glpi/ajax/getDropDownValue.php endpoint, allowing for Cross Site Scripting (XSS) attacks. This can lead to privilege escalation and the execution of JavaScript code on the admin interface. The attack involves a user creating a ticket, an admin opening another ticket and using the "Link Tickets" feature, which triggers a request to the vulnerable endpoint, fetching and executing JavaScript code.Recommendations:
For GLPI version 9.3.1, as a temporary workaround, consider disabling the "Link Tickets" feature until a patch is available. Restrict access to the
/glpi/ajax/getDropDownValue.php endpoint to minimize the risk of exploitation. Avoid using the "Link Tickets" feature in the affected version until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glpi