PT-2021-14422 · Glpi +1 · Glpi +1
Lbpierre
+1
·
Published
2021-03-08
·
Updated
2024-05-22
·
CVE-2021-21325
CVSS v3.1
6.2
6.2
Medium
Base vector | Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
GLPI versions prior to 9.5.4
Description:
The issue affects GLPI, an open-source asset and IT management software package. It allows users to define a new budget type, but the input is not correctly filtered, resulting in a cross-site scripting attack. To exploit this, an attacker needs to be authenticated.
Recommendations:
For versions prior to 9.5.4, update to version 9.5.4 to resolve the issue. As a temporary workaround, consider restricting access to the budget type definition feature to minimize the risk of exploitation.
Exploit
Fix
XSS
Weakness Enumeration
Related Identifiers
ALT-PU-2021-1583
ALT-PU-2021-1660
ALT-PU-2024-8094
CVE-2021-21325
GHSA-M574-F3JW-PWRF
Affected Products
Alt Linux
Glpi
References · 127
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/glpi_htmlawed_php_injection.rb⭐ 34948 🔗 14186 · Exploit
- 🔥 https://github.com/cactuschibre/CVE-2022-35914-poc⭐ 47 🔗 12 · Exploit
- 🔥 https://github.com/cosad3s/CVE-2022-35914-poc⭐ 47 🔗 12 · Exploit
- 🔥 https://github.com/Wangyanan131/CVE-2022-31061⭐ 3 🔗 3 · Exploit
- 🔥 https://github.com/Vu0r1-sec/CVE-2022-31061⭐ 1 🔗 1 · Exploit
- https://safe-surf.ru/specialists/bulletins-nkcki/674676 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28632 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39210 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21312 · Security Note
- https://errata.altlinux.org/ALT-PU-2021-1583 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26212 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11031 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36112 · Security Note
- https://osv.dev/vulnerability/CVE-2021-21325 · Vendor Advisory
- https://bdu.fstec.ru/vul/2023-03388 · Security Note