{ "id": "CVE-2024-27104", "sourceIdentifier": "security-advisories@github.com", "published": "2024-03-18T17:15:06.890", "lastModified": "2024-03-18T19:40:00.173", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13.\n" }, { "lang": "es", "value": "GLPI es un paquete gratuito de software de gesti\u00f3n de TI y activos, gesti\u00f3n de centros de datos, ITIL Service Desk, seguimiento de licencias y auditor\u00eda de software. Un usuario con derechos para crear y compartir paneles puede crear un panel que contenga c\u00f3digo javascript. Cualquier usuario que abra este panel estar\u00e1 sujeto a un ataque XSS. Este problema se solucion\u00f3 en la versi\u00f3n 10.0.13." } ], "metrics": { "cvssMetricV31": [ { "source": "security-advisories@github.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 0.9, "impactScore": 3.6 } ] }, "weaknesses": [ { "source": "security-advisories@github.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "references": [ { "url": "https://github.com/glpi-project/glpi/commit/b409ca437864607b03c2014b9e3293b7f141af65", "source": "security-advisories@github.com" }, { "url": "https://github.com/glpi-project/glpi/releases/tag/10.0.13", "source": "security-advisories@github.com" }, { "url": "https://github.com/glpi-project/glpi/security/advisories/GHSA-prc3-cx5m-h5mj", "source": "security-advisories@github.com" } ] }