PT-2022-7407 · Glpi+2 · Glpi+2

Ariane

+1

·

Published

2022-04-21

·

Updated

2024-07-26

·

CVE-2022-24868

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.0
Description The issue is related to a lack of sanitization on SVG file uploads, allowing an attacker to inject javascript into a user's avatar. This can lead to a cross-site scripting attack when any user views the avatar. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited. The vulnerability can be exploited by uploading a specially crafted SVG file, which allows the attacker to conduct a cross-site scripting attack. Technical details about exploitation include the lack of sanitization on SVG file uploads and the ability to inject javascript into the user avatar.
Recommendations For versions prior to 10.0.0, users are advised to upgrade to a newer version. As a temporary workaround, users unable to upgrade should disallow SVG avatars to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1914
ALT-PU-2022-2177
ALT-PU-2022-2221
ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2023-7633
ALT-PU-2024-8030
ALT-PU-2024-8094
BDU:2024-05819
CVE-2022-24868
GHSA-9HG4-FPWV-GX78

Affected Products

Alt Linux
Glpi
Red Os