Vulnerability CVE-2023-28639: Information

Description

GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malicious link can be crafted by an unauthenticated user. It will be able to exploit a reflected XSS in case any authenticated user opens the crafted link. This issue is fixed in versions 9.5.13 and 10.0.7.

Severity: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Published: April 5, 2023
Modified: April 12, 2023
Error type identifier: CWE-79

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glpisisyphus10.0.7-alt110.0.14-alt1ALT-PU-2023-1801-1320515Fixed
glpisisyphus_e2k10.0.7-alt110.0.14-alt1ALT-PU-2023-3527-1-Fixed
glpip109.5.13-alt110.0.14-alt1ALT-PU-2023-1932-1322040Fixed
glpip10_e2k9.5.13-alt110.0.14-alt1ALT-PU-2023-3790-1-Fixed
glpip99.5.13-alt19.5.13-alt1ALT-PU-2023-2081-1323561Fixed
glpip9_e2k9.5.13-alt19.5.13-alt1ALT-PU-2023-5377-1-Fixed
glpip9_mipsel9.5.13-alt19.5.13-alt1ALT-PU-2023-6334-1-Fixed
glpic10f19.5.13-alt19.5.13-alt1ALT-PU-2023-5122-3327798Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      10.0.0
      End excliding
      10.0.7

      cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
      Start including
      0.85
      End excliding
      9.5.13