CVE-2024-45609
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Nov 15, 2024
CWE ID 79
Summary
CVE-2024-45609 is a reflected Cross-Site Scripting (XSS) vulnerability affecting GLPI, a free IT management software. An unauthenticated user can manipulate reports pages by providing a malicious link to a GLPI technician, potentially injecting malicious scripts into the victim's browser. This issue poses a serious risk as it allows attackers to steal sensitive information or gain unauthorized access. To mitigate this risk, it is strongly recommended to upgrade to the latest version, 10.0.17, as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GLPI Project
Affected Vendors
- Teclib