CVE-2024-23645: GLPI reflected XSS in reports pages
Published Feb 1, 2024
·Updated
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=0.65<10.0.12
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.12
Event History
Feb 1, 2024
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23645?
CVE-2024-23645 has a high severity due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-23645?
To fix CVE-2024-23645, upgrade GLPI to version 10.0.12 or later.
3
What is affected by CVE-2024-23645?
CVE-2024-23645 affects all versions of GLPI prior to 10.0.12.
4
What type of vulnerability is CVE-2024-23645?
CVE-2024-23645 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-23645 be exploited remotely?
Yes, CVE-2024-23645 can be exploited remotely through malicious URLs.