CVE-2023-22722

GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make actions as the victim or exfiltrate session cookies. This issue is patched in version 10.0.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
Summary
  • (es) GLPI es un paquete gratuito de software de gestión de TI y activos. Las versiones 9.4.0 y superiores, anteriores a la 10.0.6, se ven afectadas por cross-site scripting. Un atacante puede persuadir a una víctima para que abra una URL que contenga un payload que aproveche esta vulnerabilidad. Después de la explotación, el atacante puede actuar como víctima o extraer cookies de sesión. Este problema se solucionó en la versión 10.0.6.
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 6.8
References () https://github.com/glpi-project/glpi/security/advisories/GHSA-352j-wr38-493c - Third Party Advisory () https://github.com/glpi-project/glpi/security/advisories/GHSA-352j-wr38-493c - Third Party Advisory

Information

Published : 2023-01-26 21:18

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22722

Mitre link : CVE-2023-22722

CVE.ORG link : CVE-2023-22722


JSON object : View

Products Affected

glpi-project

  • glpi
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')