Impact
An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a malicious payload to triggger a stored XSS.
Patches
Upgrade to 10.0.17.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.
Impact
An authenticated user can bypass the access control policy to create a private RSS feed attached to another user account and use a malicious payload to triggger a stored XSS.
Patches
Upgrade to 10.0.17.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.