GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a cross site scripting vulnerability in Kanban by injecting HTML code in its user name. Users are advised to upgrade. There are no known workarounds for this issue.
{
"cwe_ids": [
"CWE-79"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24876.json"
}{
"cpe": [
"cpe:2.3:a:glpi-project:glpi:10.0.0:-:*:*:*:*:*:*",
"cpe:2.3:a:glpi-project:glpi:10.0.0:beta:*:*:*:*:*:*",
"cpe:2.3:a:glpi-project:glpi:10.0.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:glpi-project:glpi:10.0.0:rc2:*:*:*:*:*:*",
"cpe:2.3:a:glpi-project:glpi:10.0.0:rc3:*:*:*:*:*:*"
],
"source": [
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "10.0.0-NA"
},
{
"last_affected": "10.0.0-NA"
},
{
"introduced": "10.0.0-beta"
},
{
"last_affected": "10.0.0-beta"
},
{
"introduced": "10.0.0-rc1"
},
{
"last_affected": "10.0.0-rc1"
},
{
"introduced": "10.0.0-rc2"
},
{
"last_affected": "10.0.0-rc2"
},
{
"introduced": "10.0.0-rc3"
},
{
"last_affected": "10.0.0-rc3"
}
]
}