CVE-2022-39371: Stored Cross-Site Scripting (XSS) through asset inventory in GLPI
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly neutralized. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.
Affected Software
Event History
Frequently Asked Questions
What is GLPI?
GLPI stands for Gestionnaire Libre de Parc Informatique and is a free Asset and IT Management Software package.
What is the vulnerability ID for GLPI?
The vulnerability ID for GLPI is CVE-2022-39371.
What is the severity of CVE-2022-39371?
The severity of CVE-2022-39371 is high with a CVSS score of 5.4.
What is the affected software version range for CVE-2022-39371?
The affected software version range for CVE-2022-39371 is from version 10.0.0 to version 10.0.4.
How can I fix the vulnerability CVE-2022-39371?
To fix the vulnerability CVE-2022-39371, you should update GLPI to a version higher than 10.0.4.