Impact
GLPI versions 11.0.0 through 11.0.5 contain an authentication flaw. An attacker who knows a user’s login credentials can bypass the system’s multi‑factor authentication and access the account as if they were the legitimate user. This flaw enables unauthorized use of the affected GLPI instance.
Affected Systems
The vulnerability affects the GLPI project, specifically versions 11.0.0 to 11.0.5 inclusive. All installations running those releases are at risk until upgraded to 11.0.6 or later.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring the attacker to possess valid user credentials – for example, through phishing or credential theft – and the flaw can be exploited without additional conditions. Based on the description, it is inferred that the attacker can perform this action remotely and gain the same privileges as the compromised account.
OpenCVE Enrichment