CVE-2016-7509Cross-site Scripting in Glpi

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 64.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 19
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDglpi-project/glpi0.90.4

🔴Vulnerability Details

1
GHSA
GHSA-5hqj-jfmc-p8qm: Cross-site scripting (XSS) vulnerability in GLPI 02022-05-17

💬Community

2
Bugzilla
CVE-2016-7507 CVE-2016-7509 glpi: Stored XSS and CSRF vulnerabilities [epel-7]2017-07-20
Bugzilla
CVE-2016-7507 CVE-2016-7509 glpi: Stored XSS and CSRF vulnerabilities2017-07-20