CVE-2024-50339: GLPI vulnerable to unauthenticated session hijacking

9.3 CVSS

Description

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.

Classification

CVE ID: CVE-2024-50339

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.3

Affected Products

Vendor: glpi-project

Product: glpi

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 19.3% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-v977-g4r9-6r72
https://github.com/glpi-project/glpi/releases/tag/10.0.17

Timeline