Skip to content

Xss Stored into Plugin metadata

High
cedric-anne published GHSA-4xfc-4v58-wjhh Apr 14, 2021

Package

No package listed

Affected versions

< 9.5.5

Patched versions

9.5.5

Description

Impact

Plugins editors can embed malicious code in plugins metadata (name, authors, description, ...). This code will be executed when displaying corresponding plugin informations on GLPI plugins management pages (i.e marketplace and plugins list).

Patches

fixed in 9.5.5

Reference

https://github.com/Kitsun3Sec/exploits/tree/master/cms/GLPI/GLPI-stored-XSS
https://n3k00n3.github.io/blog/09042021/glpi_xss.html

Severity

High

CVE ID

CVE-2021-3486

Weaknesses

Credits