Skip to content

Cross Site CSS Injection

Moderate
trasher published GHSA-p94c-8qp5-gfpx Apr 21, 2022

Package

glpi (glpi-project)

Affected versions

>= 0.90

Patched versions

10.0.0

Description

One can use ticket's followups or setup login messages with a stylesheet link to have this last loaded by the browser.
The issue is mitigated by cors security of browsers.

Impact

Any GLPI >= 0.90

Patches

Upgrade to 10.0.0 (or 9.5.8 if any)

For more information

If you have any questions or comments about this advisory:

mail us at glpi-security@ow2.org

Severity

Moderate

CVE ID

CVE-2022-24869

Weaknesses

No CWEs

Credits