CVE-2024-47760: GLPI vulnerable to account takeover via API
Published Dec 11, 2024
·Updated
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
Affected Software
2 affected components
GLPI GLPI>=9.1.0<10.0.17
GLPI-PROJECT GLPI>=9.1.0<10.0.17
Event History
Dec 11, 2024
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47760?
CVE-2024-47760 is considered a high-severity vulnerability due to the potential for unauthorized privilege escalation.
2
How do I fix CVE-2024-47760?
To fix CVE-2024-47760, upgrade GLPI to version 10.0.17 or later.
3
What versions of GLPI are affected by CVE-2024-47760?
CVE-2024-47760 affects GLPI versions from 9.1.0 up to, but not including, 10.0.17.
4
Can a technician with limited access exploit CVE-2024-47760?
Yes, a technician with access to the API can exploit CVE-2024-47760 to gain higher privileges.
5
Is there a patch available for CVE-2024-47760?
Yes, a patch for CVE-2024-47760 is included in GLPI version 10.0.17.