GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 11.0.0
A vulnerability in GLPI, an open-source asset and IT management software, allows a malicious actor with knowledge of a user's credentials to bypass multi-factor authentication (MFA) and take over the account. This issue affects GLPI versions 11.0.0 prior to 11.0.6.
Exploitation of this vulnerability allows for unauthorized account access by bypassing multi-factor authentication.
Users are advised to upgrade to GLPI version 11.0.6, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.