Unrated severityNVD Advisory· Published Nov 15, 2024· Updated Nov 21, 2024
GLPI has a stored XSS via document upload
CVE-2024-47759
Description
GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.
Affected products
1- Range: >= 9.2.0, < 10.0.17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/glpi-project/glpi/security/advisories/GHSA-474f-9vpp-xxq5mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.