Vulnerability Description
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | >= 0.68.1, < 9.4.6 |
Related Weaknesses (CWE)
References
- https://github.com/glpi-project/glpi/commit/5e1c52c5e8a30ceb4e9572964da7ed89ddfbPatchThird Party Advisory
- https://github.com/glpi-project/glpi/security/advisories/GHSA-3xxh-f5p2-jg3hPatchThird Party Advisory
- https://github.com/glpi-project/glpi/commit/5e1c52c5e8a30ceb4e9572964da7ed89ddfbPatchThird Party Advisory
- https://github.com/glpi-project/glpi/security/advisories/GHSA-3xxh-f5p2-jg3hPatchThird Party Advisory
FAQ
What is CVE-2020-11062?
CVE-2020-11062 is a vulnerability with a CVSS score of 6.0 (MEDIUM). In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.
How severe is CVE-2020-11062?
CVE-2020-11062 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11062?
Check the references section above for vendor advisories and patch information. Affected products include: Glpi-Project Glpi.