CVE-2022-39373: fallo de gravedad media en glpi-project glpi
Stored Cross-Site Scripting (XSS) in entity name in GLPI
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.9epss 0.5%
probabilidad de explotación
0.5%top 61% de las CVE
explotación observada
noninguna fuente lo reporta
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Administrator may store malicious code in entity name. This issue has been patched, please upgrade to version 10.0.4.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Productos afectados
glpi-project · glpiCVEs relacionadas — glpi-project glpi
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-24799HIGHGLPI allows unauthenticated SQL injection through the inventory endpointEPSS 86.7%CVE-2020-15175HIGHUnauthenticated File Deletion in GLPIEPSS 71.5%CVE-2023-46727HIGHGLPI SQL injection through inventory agent requestEPSS 67.7%CVE-2024-29889HIGHGLPI contains an SQL injection through the saved searchesEPSS 63.0%CVE-2024-31456HIGHGLPI contains an authenticated SQL injectionEPSS 59.1%CVE-2024-27096HIGHSQL Injection in through the search engineEPSS 58.8%