CVE-2023-28639: XSS
GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malicious link can be crafted by an unauthenticated user. It will be able to exploit a reflected XSS in case any authenticated user opens the crafted link. This issue is fixed in versions 9.5.13 and 10.0.7.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28639?
CVE-2023-28639 is a vulnerability in GLPI, a free asset and IT management software package, that allows an unauthenticated user to craft a malicious link and exploit a reflected XSS in case any authenticated user opens the link.
What is the severity of CVE-2023-28639?
The severity of CVE-2023-28639 is medium (6.1).
Which versions of GLPI are affected by CVE-2023-28639?
Versions 0.85 to 9.5.13 and versions 10.0.0 to 10.0.7 of GLPI are affected by CVE-2023-28639.
How can an unauthenticated user exploit CVE-2023-28639?
An unauthenticated user can craft a malicious link and if any authenticated user opens the link, the reflected XSS vulnerability will be exploited.
Is there a fix available for CVE-2023-28639?
Yes, this issue is fixed in version 9.5.13 and 10.0.7 of GLPI.