First published: Mon Mar 18 2024(Updated: )
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | >=9.5.0<10.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27104 has been classified as a high severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2024-27104, upgrade GLPI to version 10.0.13 or later.
CVE-2024-27104 affects GLPI versions from 9.5.0 to 10.0.12 inclusive.
CVE-2024-27104 can allow an attacker to execute arbitrary JavaScript code in the context of the user's browser.
Any user with rights to create and share dashboards in GLPI can exploit CVE-2024-27104.