Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-28852

Опубликовано: 05 апр. 2023
Источник: debian
EPSS Низкий

Описание

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 9.5.13 and 10.0.7, a user with dashboard administration rights may hack the dashboard form to store malicious code that will be executed when other users will use the related dashboard. Versions 9.5.13 and 10.0.7 contain a patch for this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glpiremovedpackage

Примечания

  • Only supported behind an authenticated HTTP zone

EPSS

Процентиль: 43%
0.00538
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 3 лет назад

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 9.5.13 and 10.0.7, a user with dashboard administration rights may hack the dashboard form to store malicious code that will be executed when other users will use the related dashboard. Versions 9.5.13 and 10.0.7 contain a patch for this issue.

CVSS3: 4.8
nvd
больше 3 лет назад

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 9.5.13 and 10.0.7, a user with dashboard administration rights may hack the dashboard form to store malicious code that will be executed when other users will use the related dashboard. Versions 9.5.13 and 10.0.7 contain a patch for this issue.

CVSS3: 4.8
fstec
больше 3 лет назад

Уязвимость системы работы с заявками и инцидентами GLPI, связанная с неправильной нейтрализацией ввода во время генерации веб-страницы, позволяющая нарушителю выполнять атаки с использованием межсайтовых сценариев

CVSS3: 8.8
altlinux
больше 3 лет назад

ALT-PU-2023-1932: package `glpi` update to version 9.5.13-alt1

CVSS3: 10
altlinux
больше 3 лет назад

ALT-PU-2023-1801: package `glpi` update to version 10.0.7-alt1

EPSS

Процентиль: 43%
0.00538
Низкий