4.8
CVSSv3

CVE-2023-22724

Published: 26/01/2023 Updated: 01/02/2023
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7

Vulnerability Summary

GLPI is a Free Asset and IT Management Software package. Versions before 10.0.6 are subject to Cross-site Scripting via malicious RSS feeds. An Administrator can import a malicious RSS feed that contains Cross Site Scripting (XSS) payloads inside RSS links. Victims who wish to visit an RSS content and click on the link will execute the Javascript. This issue is patched in 10.0.6.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi

Github Repositories

CVE-2023-22724 GLPI is a Free Asset and IT Management Software package Versions prior to 1006 are subject to Cross-site Scripting via malicious RSS feeds An Administrator can import a malicious RSS feed that contains Cross Site Scripting (XSS) payloads inside RSS links Victims who wish to visit an RSS content and click on the link will execute the Javascript This issue is