Reflected XSS Vulnerability in GLPI IT Management Software
CVE-2024-41678
6.1MEDIUM
Key Information:
- Vendor
- Glpi-project
- Status
- Glpi
- Vendor
- CVE Published:
- 15 November 2024
Summary
GLPI, a free asset and IT management software, has a reflected XSS vulnerability that allows an unauthenticated user to send a specially crafted link to a GLPI technician. If exploited, this vulnerability could lead to unauthorized actions being performed with the permissions of the technician. The issue affects versions of GLPI prior to 10.0.17, emphasizing the importance of upgrading to this version to mitigate the risk.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published