CVE-2019-12724: XSS
Published Jul 10, 2019
·Updated
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $POST['name'] parameter.
Affected Software
1 affected component
Teclib-edition News Glpi<=1.5.2
Remediation
Patch Available
Event History
Jul 10, 2019
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12724?
CVE-2019-12724 is a vulnerability in the Teclib News plugin for GLPI that allows a stored XSS attack.
2
How severe is CVE-2019-12724?
CVE-2019-12724 has a severity rating of medium with a CVSS score of 6.1.
3
Which version of the Teclib News plugin is affected by CVE-2019-12724?
The Teclib News plugin version 1.5.2 for GLPI is affected by CVE-2019-12724.
4
How can CVE-2019-12724 be exploited?
CVE-2019-12724 can be exploited through a stored XSS attack via the $_POST['name'] parameter.
5
Is there a fix for CVE-2019-12724?
Yes, the issue has been fixed in version 1.5.3 of the Teclib News plugin.