PT-2022-24938 · Glpi+1 · Glpi+1

Trasher

+1

·

Published

2022-09-15

·

Updated

2024-05-22

·

CVE-2022-39373

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.4
Description The issue allows an administrator to store malicious code in an entity name. This can potentially lead to security breaches. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 10.0.4, upgrade to version 10.0.4 to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2022-3008
ALT-PU-2023-7633
ALT-PU-2024-8030
ALT-PU-2024-8094
CVE-2022-39373
GHSA-CW37-Q82C-W546

Affected Products

Alt Linux
Glpi