Lucene search

K
cve[email protected]CVE-2022-31187
HistorySep 14, 2022 - 6:15 p.m.

CVE-2022-31187

2022-09-1418:15:10
CWE-79
web.nvd.nist.gov
15
4
glpi
gestionnaire libre de parc informatique
it management software
html tag vulnerability
cve-2022-31187
nvd

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H

0.001 Low

EPSS

Percentile

19.4%

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions were found to not properly neutralize HTML tags in the global search context. Users are advised to upgrade to version 10.0.3 to resolve this issue. Users unable to upgrade should disable global search.

Affected configurations

Vulners
NVD
Node
glpi-projectglpiRange10.0.010.0.3
VendorProductVersionCPE
glpi\-projectglpi*cpe:2.3:a:glpi\-project:glpi:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "glpi",
    "vendor": "glpi-project",
    "versions": [
      {
        "status": "affected",
        "version": ">= 10.0.0, < 10.0.3"
      }
    ]
  }
]

Social References

More

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H

0.001 Low

EPSS

Percentile

19.4%

Related for CVE-2022-31187