Impact
An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar.
Patches
Upgrade to 10.0.13.
Workarounds
Do not use the debug mode.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.
Impact
An unauthenticated user can provide a malicious link to a GLPI administrator in order to exploit a reflected XSS vulnerability. The XSS will only trigger if the administrator navigates through the debug bar.
Patches
Upgrade to 10.0.13.
Workarounds
Do not use the debug mode.
For more information
If you have any questions or comments about this advisory, mail us at glpi-security@ow2.org.