VYPR
Unrated severityNVD Advisory· Published Apr 5, 2023· Updated Feb 10, 2025

GLPI vulnerable to stored Cross-site Scripting in external links

CVE-2023-28636

Description

GLPI is a free asset and IT management software package. Starting in version 0.60 and prior to versions 9.5.13 and 10.0.7, a vulnerability allows an administrator to create a malicious external link. This issue is fixed in versions 9.5.13 and 10.0.7.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.