First published: Wed Dec 11 2024(Updated: )
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
>=9.1.0<10.0.17 | ||
Teclib GLPI | >=9.1.0<10.0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47760 is considered a high-severity vulnerability due to the potential for unauthorized privilege escalation.
To fix CVE-2024-47760, upgrade GLPI to version 10.0.17 or later.
CVE-2024-47760 affects GLPI versions from 9.1.0 up to, but not including, 10.0.17.
Yes, a technician with access to the API can exploit CVE-2024-47760 to gain higher privileges.
Yes, a patch for CVE-2024-47760 is included in GLPI version 10.0.17.