CVE-2024-47758: GLPI vulnerable to account takeover without privilege escalation through the API

7.6 CVSS

Description

GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.

Classification

CVE ID: CVE-2024-47758

CVSS Base Severity: HIGH

CVSS Base Score: 7.6

Affected Products

Vendor: glpi-project

Product: glpi

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-3r4x-6pmx-phwr
https://github.com/glpi-project/glpi/releases/tag/10.0.17

Timeline