CVE-2020-11062
Published
CVSS v3
6
MEDIUM
CVSS v2
3.5
LOW
Affected
1
PROJECT
Description
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6.
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.