CVE-2024-48912

HIGH

GLPI 10.0.0-10.0.16 - Authenticated Arbitrary User Account Deletion via Application Endpoint

Title source: llm
STIX 2.1

Description

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0047
EPSS Percentile 64.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
glpi-project/glpi 10.0.0 - 10.0.17
Published Dec 11, 2024
Tracked Since Feb 18, 2026