GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 9.5.0, < 11.0.0
- >= 11.0.0
A vulnerability exists in GLPI versions 9.5.0 prior to 10.0.25 and 11.0.0 prior to 11.0.7, allowing low privilege users with access to planning to delete any object within the application. This issue arises from inadequate permission controls, enabling unauthorized deletion of items.
Exploitation of this vulnerability allows for the arbitrary deletion of objects in GLPI by users with planning access.
Users can upgrade to GLPI versions 10.0.25 or 11.0.7 to address this vulnerability. As an alternative, delete rights for User's planning can be disabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.