CVE-2024-47760

Severity CVSS v4.0:
HIGH
Type:
CWE-284 Improper Access Control
Publication date:
11/12/2024
Last modified:
23/01/2025

Description

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* 9.1.0 (including) 10.0.17 (excluding)