GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 0.71
A session stealing vulnerability has been identified in GLPI (Gestionnaire Libre de Parc Informatique) versions 0.71 and 0.71 prior to 10.0.23 and 11.0.5. When remote authentication is utilized, based on Single Sign-On (SSO) variables, a user can hijack a GLPI session that was previously opened by another user on the same machine.
Exploitation of this vulnerability allows for session hijacking, where an attacker can take over another user's session.
Users are advised to upgrade to GLPI versions 10.0.23 or 11.0.5.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.