CVE-2019-14666
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.
GLPI versiones hasta 9.4.3, es propenso a la toma de control de cuentas mediante el abuso de la funcionalidad autocompletion del archivo ajax/autocompletion.php. La falta de comprobación correcta conlleva a la recuperación del token generado por medio de la funcionalidad password reset y, por lo tanto, un atacante autenticado puede establecer una contraseña arbitraria para cualquier usuario. Esta vulnerabilidad puede ser explotada para tomar el control de la cuenta de administrador. También se puede abusar de esta vulnerabilidad para obtener otros campos confidenciales como claves de la API o los hashes de contraseñas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-05 CVE Reserved
- 2019-09-25 CVE Published
- 2024-05-10 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/glpi-project/glpi/security/advisories/GHSA-47hq-pfrr-jh5q | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.tarlogic.com/advisories/Tarlogic-2019-GPLI-Account-Takeover.txt | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Glpi-project Search vendor "Glpi-project" | Glpi Search vendor "Glpi-project" for product "Glpi" | <= 9.4.3 Search vendor "Glpi-project" for product "Glpi" and version " <= 9.4.3" | - |
Affected
|