PT-2022-24937 · Glpi+1 · Glpi+1

Jordy Provost

·

Published

2022-09-15

·

Updated

2024-05-22

·

CVE-2022-39371

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.4
Description The issue concerns the improper neutralization of script related HTML tags in assets inventory information. This has been patched, and an upgrade is recommended. There are no known workarounds at this time.
Recommendations For versions prior to 10.0.4, upgrade to version 10.0.4 to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2022-3008
ALT-PU-2023-7633
ALT-PU-2024-8030
ALT-PU-2024-8094
CVE-2022-39371
GHSA-W7WC-728F-6MM8

Affected Products

Alt Linux
Glpi