Description
An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before 11.0.7.
Problem types
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Product status
Any version before 11.0.7
Credits
Fluid Attacks' AI SAST Scanner
Oscar Uribe
References
fluidattacks.com/es/advisories/bizkit
fluidattacks.com/es/advisories/bizkit
github.com/glpi-project/glpi
github.com/...t/glpi/security/advisories/GHSA-2fg5-jg72-h338
github.com/glpi-project/glpi/releases/tag/11.0.7