CVE-2023-28636: GLPI vulnerable to stored Cross-site Scripting in external links
Published Apr 5, 2023
·Updated
GLPI is a free asset and IT management software package. Starting in version 0.60 and prior to versions 9.5.13 and 10.0.7, a vulnerability allows an administrator to create a malicious external link. This issue is fixed in versions 9.5.13 and 10.0.7.
Affected Software
2 affected components
GLPI-PROJECT GLPI>=0.60<9.5.13
GLPI-PROJECT GLPI>=10.0.0<10.0.7
Remediation
Patch Available
Patch Available
Event History
Apr 5, 2023
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this GLPI vulnerability?
The vulnerability ID for this GLPI vulnerability is CVE-2023-28636.
2
What is GLPI?
GLPI is a free asset and IT management software package.
3
What is the severity of CVE-2023-28636?
The severity of CVE-2023-28636 is medium with a CVSS score of 4.8.
4
How does CVE-2023-28636 affect GLPI?
CVE-2023-28636 allows an administrator to create a malicious external link in GLPI versions 0.60 to 9.5.13 and 10.0.0 to 10.0.7.
5
How can I fix CVE-2023-28636 in GLPI?
To fix CVE-2023-28636 in GLPI, update to version 9.5.13 or 10.0.7 or later.