Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GLPI - CVE-2022-35945
Published: September 14, 2022 / Updated: May 4, 2026
GLPI
glpi-project
Description
The vulnerability allows a remote user to steal an administrator cookie.
The vulnerability exists due to improper neutralization of script-related html tags in the registration key configuration page when rendering information associated with a registration key. A remote user can create a crafted registration key to steal an administrator cookie.