Unrated severityNVD Advisory· Published Apr 21, 2022· Updated Apr 23, 2025
Cross site scripting via SVG file upload in GLPI
CVE-2022-24868
Description
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a result any user viewing the avatar will be subject to a cross site scripting attack. Users of GLPI are advised to upgrade. Users unable to upgrade should disallow SVG avatars.
Affected products
1- Range: < 10.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/glpi-project/glpi/commit/1aa9fcc4741a46fa5a9f11d71b409b911ffc190fmitrex_refsource_MISC
- github.com/glpi-project/glpi/security/advisories/GHSA-9hg4-fpwv-gx78mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.