Glpi Product vulnerabilities
2 known vulnerabilities affecting glpi/glpi_product.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2019-1010307MEDIUMCVSS 5.4v9.3.12019-07-15
CVE-2019-1010307 [MEDIUM] CWE-79 CVE-2019-1010307: GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown valu
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the "Link Tickets" fea
nvd
CVE-2019-1010310LOWCVSS 3.5v9.3.1 [fixed: 9.4.1]2019-07-12
CVE-2019-1010310 [LOW] CWE-74 CVE-2019-1010310: GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack
nvd