Reflected XSS Vulnerability in GLPI IT Management Software
CVE-2024-41678
6.1MEDIUM
What is CVE-2024-41678?
GLPI, a free asset and IT management software, has a reflected XSS vulnerability that allows an unauthenticated user to send a specially crafted link to a GLPI technician. If exploited, this vulnerability could lead to unauthorized actions being performed with the permissions of the technician. The issue affects versions of GLPI prior to 10.0.17, emphasizing the importance of upgrading to this version to mitigate the risk.