Sploitus

CVE-2024-50339

No indexed exploits for CVE-2024-50339 yet

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.

Affected products
Alt Linux, Glpi, Red Os
Glpi-project Glpi
< 10.0.17
Fix
Available
CVSS 4.0
9.3 CRITICAL
CVSS 3.1
5.3 MEDIUM
EPSS
19.6% (97th percentile)
Weakness
CWE-384, CWE-79, CWE-287
NVD status
Analyzed
Published
2024-12-11
CVE-2024-50339 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-50339 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-50339 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.