GLPI has a stored XSS via document upload
CVE-2024-47759
4.8MEDIUM
What is CVE-2024-47759?
GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.
Affected Version(s)
glpi >= 9.2.0, < 10.0.17