CVE-2021-21325 – GLPI is an open-source asset and IT management software package that provides ITIL Service …

Vuln ID: CVE-2021-21325

Published:  2021-03-08  17:15:12Z

Description: GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 a new budget type can be defined by user. This input is not correctly filtered. This results in a cross-site scripting attack. To exploit this endpoint attacker need to be authenticated. This is fixed in version 9.5.4.

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):