Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-37147 PoC — GLPI allows Authenticated File Upload to Restricted Tickets

Source
Associated Vulnerability
Title:GLPI allows Authenticated File Upload to Restricted Tickets (CVE-2024-37147)
Description:GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.
Readme
# CVE-2024-37147-PoC

Blog Post with Poc for CVE-2024-37147: https://0xmupa.github.io/glpi-file-upload/
File Snapshot

[4.0K] /data/pocs/c831bb5e33eb6bdf66d3031d60ceb8ebeeade4e1 └── [ 104] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →