{"id":"CVE-2018-7563","details":"An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.","modified":"2026-08-07T14:59:33.916346Z","published":"2018-03-12T21:29:01.203Z","references":[{"type":"REPORT","url":"https://github.com/glpi-project/glpi/pull/3647"},{"type":"REPORT","url":"https://membership.backbox.org/glpi-9-2-1-multiple-vulnerabilities/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/glpi-project/glpi","events":[{"introduced":"0"},{"last_affected":"3a7c5969c0534d0b5bf27fef9c4d96f56147ae66"}],"database_specific":{"cpe":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"9.2.1"}],"source":"CPE_RANGE"}}],"versions":["9.2.1","9.2","9.2-RC2","9.2-RC1","9.1","9.1-RC2","9.1-RC1","0.90","0.90-RC2","0.90-RC1","0.90-beta2","0.90-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7563.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}