Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42831 | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 23 Jan 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Glpi-project
Glpi-project glpi |
|
| CPEs | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Glpi-project
Glpi-project glpi |
|
| Metrics |
cvssV3_1
|
Thu, 12 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue. | |
| Title | GLPI vulnerable to account takeover via the password reset feature | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-12T15:15:33.980Z
Reserved: 2024-09-30T21:28:53.231Z
Link: CVE-2024-47761
Updated: 2024-12-12T15:15:29.991Z
Status : Analyzed
Published: 2024-12-11T17:15:16.753
Modified: 2025-01-23T20:37:11.150
Link: CVE-2024-47761
No data.
OpenCVE Enrichment
No data.
EUVD