CVE-2024-47760: GLPI-Project GLPI

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

Affected products

  • GLPI-Project GLPI: from 9.1.0, before 10.0.17 (fixed in 10.0.17)

Published 2024-12-11. Last modified 2026-06-17.