CVE-2019-12724
10.07.2019, 14:15
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
Vendor | Product | Version |
---|---|---|
teclib-edition | news | 𝑥 ≤ 1.5.2 |
𝑥
= Vulnerable software versions
References