CVE-2020-11062: Reflexive XSS in GLPI
Published May 12, 2020
·Updated
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=0.68.1<9.4.6
Remediation
Event History
May 12, 2020
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-11062?
CVE-2020-11062 has a moderate severity rating due to the potential for multiple reflexive XSS attacks.
2
How do I fix CVE-2020-11062?
To fix CVE-2020-11062, you should upgrade GLPI to version 9.4.6 or later.
3
Which versions of GLPI are affected by CVE-2020-11062?
GLPI versions between 0.68.1 and 9.4.5 are affected by CVE-2020-11062.
4
What type of vulnerability is CVE-2020-11062?
CVE-2020-11062 is classified as a cross-site scripting (XSS) vulnerability.
5
Are there any known exploits for CVE-2020-11062?
There are no public exploits documented for CVE-2020-11062 as of now.