CyberRota Analysis
AI-GeneratedThe vulnerability affects GLPI versions 11.0.0 to 11.0.8, where the time-based one-time password (TOTP) verification endpoint lacks restrictions on failed submission attempts per user. This flaw allows attackers with a user's primary credentials to perform brute-force attacks on the multi-factor authentication (MFA) process, potentially leading to account takeover. Organizations using affected versions of GLPI should prioritize upgrading to version 11.0.8 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification flow, making brute-force compromise of the second factor and subsequent account takeover possible. This issue is fixed in version 11.0.8.