CVE-2022-41941: glpi contains XSS Stored inside Standard Interface Help Link href attribute
Published Jan 25, 2023
·Updated
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in 10.0.6.
Affected Software
2 affected components
GLPI-PROJECT GLPI>=0.70<9.5.12
GLPI-PROJECT GLPI>=10.0.0<10.0.6
Event History
Jan 25, 2023
CVE Published
via MITRE·06:06 AM
Data Sourced
via MITRE·06:06 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-41941?
CVE-2022-41941 is a Cross-site Scripting vulnerability in GLPI versions 10.0.0 and above, prior to 10.0.6.
2
What is the severity of CVE-2022-41941?
The severity of CVE-2022-41941 is medium with a CVSS score of 4.8.
3
How does CVE-2022-41941 impact GLPI?
CVE-2022-41941 allows an administrator to store malicious code in help links, potentially leading to cross-site scripting attacks.
4
Is CVE-2022-41941 patched?
Yes, CVE-2022-41941 is patched in version 10.0.6 of GLPI.
5
What can I do to mitigate CVE-2022-41941?
To mitigate CVE-2022-41941, you should update your GLPI installation to version 10.0.6 or above.