Medium severity6.1NVD Advisory· Published Jul 10, 2019· Updated Jun 17, 2026
CVE-2019-12724
CVE-2019-12724
Description
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Teclib/News plugindescription
- Range: <=1.5.2
Patches
Vulnerability mechanics
References
3- github.com/pluginsGLPI/news/pull/69nvdPatchThird Party Advisory
- github.com/pluginsGLPI/news/blob/master/front/alert.form.phpnvdThird Party Advisory
- github.com/pluginsGLPI/news/releases/tag/1.5.3nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.