GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it.
id: CVE-2024-29889
info:
name: GLPI 10.0.10-10.0.14 - SQL Injection
author: iamnoooob,rootxhars
...