CVE-2024-27930
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 18, 2024
Updated: Jan 2, 2025
CWE ID 285
Summary
CVE-2024-27930 is a vulnerability affecting GLPI, a popular Free Asset and IT Management Software package. An authenticated user with read access to an item can access sensitive fields, potentially exposing confidential data. This issue has been addressed in GLPI version 10.0.13, and users are encouraged to update to the latest patch level to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GLPI Project
- Glpi-project GLPI
Affected Vendors
- Teclib
- Glpi-project