Vulnerabilities > CVE-2024-27098 - Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi

047910
CVSS 9.6 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
glpi-project
CWE-918
critical

Summary

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13.

Common Weakness Enumeration (CWE)