GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/glpi-project/glpi/releases/tag/10.0.17 | Release Notes | 
| https://github.com/glpi-project/glpi/security/advisories/GHSA-x794-564w-vgxx | Vendor Advisory | 
Configurations
                    History
                    23 Jan 2025, 20:37
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.2 | 
| Summary | 
 | |
| References | () https://github.com/glpi-project/glpi/releases/tag/10.0.17 - Release Notes | |
| References | () https://github.com/glpi-project/glpi/security/advisories/GHSA-x794-564w-vgxx - Vendor Advisory | |
| CPE | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| First Time | Glpi-project Glpi-project glpi | 
11 Dec 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-11 17:15
Updated : 2025-01-23 20:37
NVD link : CVE-2024-47761
Mitre link : CVE-2024-47761
CVE.ORG link : CVE-2024-47761
JSON object : View
Products Affected
                glpi-project
- glpi
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
