PT-2024-10159 · Glpi+2 · Glpi+2

Guervild

·

Published

2024-10-10

·

Updated

2025-08-13

·

CVE-2024-48912

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions 0.80 through 10.0.16
Description GLPI is a free asset and IT management software package. The issue is related to incorrect access control, allowing an authenticated user to use an application endpoint to delete any user account.
Recommendations For versions 0.80 through 10.0.16, update to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the application endpoint that allows user account deletion until the update is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2025-00485
CVE-2024-48912
GHSA-VJMW-J32J-PH4F

Affected Products

Alt Linux
Glpi
Red Os