CVE-2024-38370: GLPI-Project GLPI
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
Affected products
- GLPI-Project GLPI: from 9.2.0, before 10.0.16 (fixed in 10.0.16)
Published 2024-11-15. Last modified 2026-06-17.