PT-2021-14422 · Glpi +1 · Glpi +1

Lbpierre

+1

·

Published

2021-03-08

·

Updated

2024-05-22

·

CVE-2021-21325

CVSS v3.1
6.2
VectorAV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N

Name of the Vulnerable Software and Affected Versions:

GLPI versions prior to 9.5.4

Description:

The issue affects GLPI, an open-source asset and IT management software package. It allows users to define a new budget type, but the input is not correctly filtered, resulting in a cross-site scripting attack. To exploit this, an attacker needs to be authenticated.

Recommendations:

For versions prior to 9.5.4, update to version 9.5.4 to resolve the issue. As a temporary workaround, consider restricting access to the budget type definition feature to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1583
ALT-PU-2021-1660
ALT-PU-2024-8094
CVE-2021-21325
GHSA-M574-F3JW-PWRF

Affected Products

Alt Linux
Glpi