← Back

CVE-2019-1010310

nvd nist
Published: Jul 12, 2019Modified: Jun 17, 2026

JSON object

Loading...
3.5
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Exploitability: 0.9 / Impact: 2.5
Source: NVD

Description

GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack vector is: The attacker puts a login form, the user fills it and clicks on submit .. the request is sent to the attacker domain saving the data. The fixed version is: 9.4.1.

Affected (1)

Products: Glpi Project: Glpi
1 product
Glpi
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.3.1

References (4)

Source: josh@bress.net
PatchThird Party Advisory
Source: josh@bress.net
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory

Timeline

No history available yet.