PT-2024-8000 · Glpi+2 · Glpi+2

Qbiguenet

·

Published

2024-11-06

·

Updated

2025-08-13

·

CVE-2024-47761

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions 0.80 through 10.0.16
Description The issue is related to a lack of password recovery mechanism in the GLPI system, which can be exploited by a remote attacker to bypass existing security restrictions. An administrator with access to the contents of sent notifications can take control of an account with higher privileges.
Recommendations For GLPI versions 0.80 through 10.0.16, update to version 10.0.17 to resolve the issue. As a temporary workaround, consider restricting access to the notification contents for administrators to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10163
ALT-PU-2025-1277
BDU:2024-09514
CVE-2024-47761
GHSA-X794-564W-VGXX

Affected Products

Alt Linux
Glpi
Red Os