CVE-2022-21719: Reflected XSS using reload button in GLPI
Published Jan 28, 2022
·Updated
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.
Affected Software
1 affected component
GLPI-PROJECT GLPI<9.5.7
Remediation
Event History
Jan 28, 2022
CVE Published
via MITRE·10:06 AM
Data Sourced
via MITRE·10:06 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-21719?
CVE-2022-21719 is a reflected cross-site scripting vulnerability in GLPI with a medium severity rating.
2
How do I fix CVE-2022-21719?
To fix CVE-2022-21719, upgrade GLPI to version 9.5.7 or later.
3
What versions are affected by CVE-2022-21719?
All GLPI versions prior to 9.5.7 are affected by CVE-2022-21719.
4
Is there a workaround for CVE-2022-21719?
There are no known workarounds for CVE-2022-21719.
5
What type of vulnerability is CVE-2022-21719?
CVE-2022-21719 is classified as a reflected cross-site scripting vulnerability.