CVE-2022-41941 MEDIUM

CVE-2022-41941: glpi contains XSS Stored inside Standard Interface Help Link href attribute

Vendor Glpi-Project
Product glpi
Weakness CWE-79 · XSS
Published January 25, 2023
Last update March 10, 2025

CVSS base score

6.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in 10.0.6.

Key dates

02Disclosure timeline

January 25, 2023 CVE published
March 10, 2025 Record updated