CVE Database
/

CVE-2019-1010310

Back to search

CVE-2019-1010310

Published: Jul 12, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack vector is: The attacker puts a login form, the user fills it and clicks on submit .. the request is sent to the attacker domain saving the data. The fixed version is: 9.4.1.

VendorProductVersions

GLPI

GLPI Product

affected
9.3.1 [fixed: 9.4.1]

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2019-1010310 - Security Vulnerability | QwikSec