Описание
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
Ссылки
- Issue Tracking
- Third Party Advisory
- ExploitThird Party Advisory
- Issue Tracking
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:glpi-project:glpi:9.5.4:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00705
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 4 лет назад
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
CVSS3: 6.1
debian
больше 4 лет назад
GLPi 9.5.4 does not sanitize the metadata. This way its possible to in ...
EPSS
Процентиль: 72%
0.00705
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79