Medium severity4.5NVD Advisory· Published Nov 3, 2022· Updated Jun 17, 2026
CVE-2022-39277
CVE-2022-39277
Description
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a Cross-Site Scripting (XSS) attack. This issue has been patched, please upgrade to GLPI 10.0.4. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: >=0.60,<10.0.4
- (no CPE)range: >=10.0.4
- (no CPE)range: >= 0.60, < 10.0.4
Patches
Vulnerability mechanics
References
2- huntr.dev/bounties/8e047ae1-7a7c-48e0-bee3-d1c36e52ff42/nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/glpi-project/glpi/security/advisories/GHSA-rhcw-8r7g-8pwcnvdThird Party Advisory
News mentions
0No linked articles in our index yet.