CVE-2024-47758: GLPI vulnerable to account takeover without privilege escalation through the API
Published Dec 11, 2024
·Updated
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.
Affected Software
2 affected components
GLPI GLPI>9.3.0<=10.0.16
GLPI-PROJECT GLPI>=9.3.0<10.0.17
Event History
Dec 11, 2024
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
May 25, 57072
Event
via NVD·09:46 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-47758?
CVE-2024-47758 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-47758?
To fix CVE-2024-47758, update GLPI to version 10.0.17 or later.
3
Who is affected by CVE-2024-47758?
CVE-2024-47758 affects authenticated users of GLPI versions 9.3.0 through 10.0.16.
4
What kind of attack is possible with CVE-2024-47758?
An attacker can use the API to take control of any user with the same or lower privilege levels.
5
Is CVE-2024-47758 fixed in previous versions prior to 10.0.17?
No, CVE-2024-47758 is not fixed in any version prior to 10.0.17.