vulnerability

FreeBSD: VID-d3f60db0-3aea-11eb-af2a-080027dbe4b7 (CVE-2019-14666): glpi -- Account takeover vulnerability

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Aug 5, 2019
Added
Dec 12, 2020
Modified
Dec 10, 2025

Description

MITRE Corporation reports: GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

Solution

freebsd-upgrade-package-glpi
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.