CVE-2024-47759: GLPI-Project GLPI

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be executed when any user will try to see the document contents. Upgrade to 10.0.17.

Affected products

  • GLPI-Project GLPI: from 9.2.0, before 10.0.17 (fixed in 10.0.17)

Published 2024-11-15. Last modified 2026-06-17.