CVE-2023-22722
MEDIUMGLPI 9.4.0-9.5.12 - Cross-Site Scripting via URL Payload
Title source: llmDescription
GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make actions as the victim or exfiltrate session cookies. This issue is patched in version 10.0.6.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/glpi-project/glpi/security/advisories/GHSA-352j-wr38-493c
Scores
CVSS v3
6.8
EPSS
0.0028
EPSS Percentile
51.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
glpi-project/glpi
9.4.0 - 9.5.12
Published
Jan 26, 2023
Tracked Since
Feb 18, 2026