First published: Wed Jan 25 2023(Updated: )
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in 10.0.6.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | >=0.70<9.5.12 | |
Teclib GLPI | >=10.0.0<10.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41941 is a Cross-site Scripting vulnerability in GLPI versions 10.0.0 and above, prior to 10.0.6.
The severity of CVE-2022-41941 is medium with a CVSS score of 4.8.
CVE-2022-41941 allows an administrator to store malicious code in help links, potentially leading to cross-site scripting attacks.
Yes, CVE-2022-41941 is patched in version 10.0.6 of GLPI.
To mitigate CVE-2022-41941, you should update your GLPI installation to version 10.0.6 or above.