GLPI Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
8 Aug. 2012
Summary
GLPI is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, to disclose or modify sensitive information, or to perform unauthorized actions. Other attacks are also possible.GLPI versions prior to 0.83.3 are vulnerable.
Vendor Status:
Currently we are not aware of any vendor-supplied patches