Title:GLPI allows Authenticated File Upload to Restricted Tickets (CVE-2024-37147) Description:GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.
Readme
# CVE-2024-37147-PoC
Blog Post with Poc for CVE-2024-37147: https://0xmupa.github.io/glpi-file-upload/
1. It is advised to access via the original source first.2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →