An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-19288 An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T06:31:04.805Z

Reserved: 2018-02-28T00:00:00

Link: CVE-2018-7563

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-12T21:29:01.203

Modified: 2024-11-21T04:12:22.397

Link: CVE-2018-7563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.