PT-2024-19996 · Glpi+2 · Glpi+2

·

CVE-2024-23645

·

Published

2022-09-15

·

Updated

2024-08-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.12
Description A malicious URL can be used to execute XSS on reports pages. This issue affects GLPI, a Free Asset and IT Management Software package.
Recommendations For versions prior to 10.0.12, upgrade to 10.0.12 to resolve the issue. As a temporary workaround, consider restricting access to reports pages until the upgrade is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2614
ALT-PU-2022-2624
ALT-PU-2022-2665
ALT-PU-2023-7633
ALT-PU-2024-2541
ALT-PU-2024-2543
ALT-PU-2024-8030
ALT-PU-2024-8094
CVE-2024-23645
GHSA-2GJ5-QPFF-FF3X

Affected Products

Alt Linux
Glpi
Red Os