PT-2024-5859 · Glpi+2 · Glpi+2

Guilhem7

·

Published

2024-07-10

·

Updated

2025-01-07

·

CVE-2024-37149

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 10.0.16
Description The issue is related to the GLPI system, which is an open-source asset and IT management software package providing ITIL Service Desk features, licenses tracking, and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the plugin loader to execute this malicious script. This is due to external control of the file name or path.
Recommendations For versions prior to 10.0.16, upgrade to 10.0.16 to resolve the issue. As a temporary workaround, consider restricting access to the plugin loader to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10022
ALT-PU-2024-9613
BDU:2024-06606
CVE-2024-37149
GHSA-CWVP-J887-M4XH

Affected Products

Alt Linux
Glpi
Red Os