Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GLPI 跨站脚本漏洞
Vulnerability Description
GLPI是Indepnet协会维护的一款开源的IT资源管理套件。该套件包含设备状态管理、资产清单存储、管理流程和工作日志管理等功能。 GLPI 9.2.1及之前版本中存在跨站脚本漏洞。远程攻击者可通过向front/preference.php文件发送查询字符串利用该漏洞执行JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A