Low severity3.5NVD Advisory· Published Jul 12, 2019· Updated Jun 17, 2026
CVE-2019-1010310
CVE-2019-1010310
Description
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack vector is: The attacker puts a login form, the user fills it and clicks on submit .. the request is sent to the attacker domain saving the data. The fixed version is: 9.4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:glpi-project:glpi:9.3.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:glpi-project:glpi:9.3.1:*:*:*:*:*:*:*
- (no CPE)range: 9.3.1
- Range: 9.3.1
- GLPI/GLPI Productv5Range: 9.3.1 [fixed: 9.4.1]
Patches
Vulnerability mechanics
References
2- github.com/glpi-project/glpi/pull/5519nvdPatchThird Party Advisory
- github.com/glpi-project/glpi/releases/tag/9.3.1nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.