inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
2019-07-04T15:15:11.200
2024-11-21T04:24:31.007
Modified
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | glpi-project | glpi | < 9.4.3 | Yes |