CVE-2019-14666

HIGH

GLPI < 9.4.3 - Authenticated Account Takeover via Autocompletion Token Exposure

Title source: llm
STIX 2.1

Description

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

References (2)

Core 2
Core References

Scores

CVSS v3 8.8
EPSS 0.0301
EPSS Percentile 86.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (1)
glpi-project/glpi < 9.4.3
Published Sep 25, 2019
Tracked Since Feb 18, 2026