We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
A malicious URL can be used to execute XSS on reports pages.
Upgrade to 10.0.12.
Remove the read rights on reports for all profiles.
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.
Impact
A malicious URL can be used to execute XSS on reports pages.
Patches
Upgrade to 10.0.12.
Workarounds
Remove the read rights on reports for all profiles.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.