CVE-2024-23645
CVSS V2 None
CVSS V3 None
Description
GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.
Overview
- CVE ID
- CVE-2024-23645
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-01T15:24:57.438Z
- Last Modified Date
- 2024-02-01T17:49:23.773Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/glpi-project/glpi/security/advisories/GHSA-2gj5-qpff-ff3x | x_refsource_CONFIRM |
https://github.com/glpi-project/glpi/commit/6cf265936c4f6edf7dea7c78b12e46d75b94d9b0 | x_refsource_MISC |
https://github.com/glpi-project/glpi/commit/fc1f6da9d158933b870ff374ed3a50ae98dcef4a | x_refsource_MISC |
https://github.com/glpi-project/glpi/releases/tag/10.0.12 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-23645 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23645 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 07:04:44 | Added to TrackCVE |