CVE-2019-14666Sensitive Information Exposure in Glpi

Severity
8.8HIGHNVD
EPSS
3.0%
top 13.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25
Latest updateMay 24

Description

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-f2c5-q3w6-4h6j: GLPI through 92022-05-24
OSV
CVE-2019-14666: GLPI through 92019-09-25

💬Community

3
Bugzilla
CVE-2019-14666 glpi: information disclosure in ajax/autocompletion.php [epel-7]2019-10-07
Bugzilla
CVE-2019-14666 glpi: information disclosure in ajax/autocompletion.php2019-10-07
Bugzilla
CVE-2019-14666 glpi: information disclosure in ajax/autocompletion.php [fedora-all]2019-10-07