PT-2024-9988 · Glpi · Addressing Glpi Plugin

Flegastelois

·

Published

2024-11-22

·

Updated

2024-12-26

·

CVE-2024-53850

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Addressing GLPI plugin versions 3.0.0 through 3.0.3
Description: The issue is related to a poor security check in the Addressing GLPI plugin, which allows an unauthenticated attacker to determine whether data exists by name in GLPI. This can potentially lead to unauthorized access to protected information. The vulnerability is associated with the use of external controlled input for selecting classes or code.
Recommendations: For versions 3.0.0 through 3.0.3, update to version 3.0.3 or later to resolve the issue. At the moment, there is no information about other versions that contain a fix for this vulnerability.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-00106
CVE-2024-53850
GHSA-FW42-79GW-7QR9

Affected Products

Addressing Glpi Plugin