Reflected XSS Vulnerability in GLPI IT Management Software
CVE-2024-41678

6.1MEDIUM

Key Information:

Vendor
Glpi-project
Status
Glpi
Vendor
CVE Published:
15 November 2024

Summary

GLPI, a free asset and IT management software, has a reflected XSS vulnerability that allows an unauthenticated user to send a specially crafted link to a GLPI technician. If exploited, this vulnerability could lead to unauthorized actions being performed with the permissions of the technician. The issue affects versions of GLPI prior to 10.0.17, emphasizing the importance of upgrading to this version to mitigate the risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.