Skip to content

XSS / open redirect via SVG file upload

Low
trasher published GHSA-9hg4-fpwv-gx78 Apr 21, 2022

Package

glpi (glpi-project)

Affected versions

<10.0.0

Patched versions

10.0.0

Description

Impact

One can exploit a XSS to redict the user by uploading a malicious svg on user's avatar

Patches

Workarounds

Do not expose the files folder to the web.

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

mail us at glpi-security@ow2.org

Severity

Low

CVE ID

CVE-2022-24868

Weaknesses

No CWEs

Credits