Vulnerability Description
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
CVSS Score
6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | >= 0.65, < 10.0.12 |
Related Weaknesses (CWE)
References
- https://github.com/glpi-project/glpi/commit/6cf265936c4f6edf7dea7c78b12e46d75b94Patch
- https://github.com/glpi-project/glpi/commit/fc1f6da9d158933b870ff374ed3a50ae98dcPatch
- https://github.com/glpi-project/glpi/releases/tag/10.0.12PatchRelease Notes
- https://github.com/glpi-project/glpi/security/advisories/GHSA-2gj5-qpff-ff3xVendor Advisory
- https://github.com/glpi-project/glpi/commit/6cf265936c4f6edf7dea7c78b12e46d75b94Patch
- https://github.com/glpi-project/glpi/commit/fc1f6da9d158933b870ff374ed3a50ae98dcPatch
- https://github.com/glpi-project/glpi/releases/tag/10.0.12PatchRelease Notes
- https://github.com/glpi-project/glpi/security/advisories/GHSA-2gj5-qpff-ff3xVendor Advisory
FAQ
What is CVE-2024-23645?
CVE-2024-23645 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
How severe is CVE-2024-23645?
CVE-2024-23645 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23645?
Check the references section above for vendor advisories and patch information. Affected products include: Glpi-Project Glpi.