CVE-2024-37147 is a medium-severity vulnerability affecting GLPI, an open-source IT asset and service management software. An authenticated user can attach documents to items even without write permissions, leading to a low-impact integrity issue. The vulnerability has a CVSS score of 4.3 (Medium) with a network attack vector and low attack complexity, but no impact on confidentiality or availability. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.85, < 10.0.16CPE matchmatch criteria | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.