CVE-2019-12724: Teclib-Edition News
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
Affected products
- Teclib-Edition News: up to and including 1.5.2
Published 2019-07-10. Last modified 2026-06-17.