ALT-PU-2026-5401-1

Обновление пакета glpi в ветке sisyphus_e2k

Версия10.0.24-alt1
Задание#0
Опубликовано2026-03-28
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (2)

CVE-2026-25932
MEDIUM4.8

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

Опубликовано: 2026-04-06Изменено: 2026-04-07
CVSS 3.xСРЕДНЯЯ 4.8
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVE-2026-29047
HIGH8.8

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

Опубликовано: 2026-04-06Изменено: 2026-04-07
CVSS 3.xВЫСОКАЯ 8.8
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Закрытые ошибки (1)