GLPI reflected XSS in reports pages
CVE-2024-23645
6.1MEDIUM
What is CVE-2024-23645?
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
Affected Version(s)
glpi >= 0.65, < 10.0.12