CVE-2024-48912 Information

Description

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17 an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.

Reference

https://github.com/glpi-project/glpi/releases/tag/10.0.17 https://github.com/glpi-project/glpi/security/advisories/GHSA-vjmw-j32j-ph4f

Share on: