PT-2024-10159 · Glpi+2 · Glpi+2

·

CVE-2024-48912

·

Published

2024-10-10

·

Updated

2025-08-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions 0.80 through 10.0.16
Description GLPI is a free asset and IT management software package. The issue is related to incorrect access control, allowing an authenticated user to use an application endpoint to delete any user account.
Recommendations For versions 0.80 through 10.0.16, update to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the application endpoint that allows user account deletion until the update is applied.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2025-00485
CVE-2024-48912
GHSA-VJMW-J32J-PH4F

Affected Products

Alt Linux
Glpi
Red Os