PT-2022-7393 · Glpi+2 · Glpi+2

Trasher

·

Published

2022-09-15

·

Updated

2024-07-26

·

CVE-2022-39372

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.4
Description The issue allows authenticated users to store malicious code in their account information, potentially leading to a cross-site scripting (XSS) attack. This could enable a remote attacker to conduct such an attack by exploiting the lack of protection measures for the web page structure.
Recommendations For versions prior to 10.0.4, upgrade to version 10.0.4 to resolve the issue. At the moment, there is no information about other workarounds for this vulnerability.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2022-3008
ALT-PU-2022-3078
ALT-PU-2022-3274
ALT-PU-2023-7633
ALT-PU-2024-8030
ALT-PU-2024-8094
BDU:2024-05805
CVE-2022-39372
GHSA-5RJ7-95QC-89H2

Affected Products

Alt Linux
Glpi
Red Os