PT-2024-10105 · Glpi+2 · Glpi+2

Anhln-3312

·

Published

2024-11-15

·

Updated

2025-08-13

·

CVE-2024-43417

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.17
Description The issue is related to a lack of protection of the web page structure in the GLPI system, which can be exploited by a remote attacker to conduct a cross-site scripting (XSS) attack. Specifically, an unauthenticated user can provide a malicious link to a GLPI technician to exploit a reflected XSS vulnerability located in the Software form.
Recommendations For versions prior to 10.0.17, upgrade to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the Software form until the upgrade is applied. Additionally, technicians should be cautious when clicking on links provided by unauthenticated users to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2025-00329
CVE-2024-43417
GHSA-P633-WFJ5-8X44

Affected Products

Alt Linux
Glpi
Red Os