CVE-2023-22722 GLPI is a Free Asset and IT Management Software package Versions 940 and above, prior to 1006 are subject to Cross-site Scripting An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability After exploited, the attacker can make actions as the victim or exfiltrate session cookies This issue is patched in version