Описание
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.1.0 (включая) до 10.0.19 (исключая)
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00069
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-80
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 1 месяца назад
GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can send a malicious link to attempt a phishing attack from the planning feature. This is fixed in version 10.0.19.
CVSS3: 6.5
debian
около 1 месяца назад
GLPI is a Free Asset and IT Management Software package. In versions 9 ...
EPSS
Процентиль: 21%
0.00069
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-80