CVE-2024-41678
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Nov 15, 2024
CWE ID 79
Summary
CVE-2024-41678 refers to a reflected Cross-Site Scripting (XSS) vulnerability in GLPI, a free IT management software. An attacker can exploit this weakness by supplying a malicious link to a GLPI technician, potentially injecting malicious code and gaining unauthorized access to user data or sessions. The vulnerability affects older versions of GLPI and can be mitigated by upgrading to version 10.0.17. It is crucial for GLPI users to apply the update promptly to prevent potential data breaches or unintended system interactions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GLPI Project
Affected Vendors
- Teclib