CVE-2018-7563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/03/2018
Last modified:
11/04/2018

Description

An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* 9.2.1 (including)