PT-2019-13768 · Teclib+1 · Glpi+1

Pablo Martinez

+1

·

Published

2019-09-25

·

Updated

2020-08-24

·

CVE-2019-14666

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions prior to 9.4.4
Description The issue allows for account takeover by exploiting the autocompletion feature in ajax/autocompletion.php due to a lack of proper validation. This enables an attacker to recover the token generated during the password reset process, allowing them to set an arbitrary password for any user, including admin accounts. Additionally, this could be used to obtain sensitive information such as API keys or password hashes.
Recommendations For versions prior to 9.4.4, update to version 9.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the ajax/autocompletion.php endpoint until a patch is applied. Avoid using the password reset functionality until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3405
ALT-PU-2020-1967
CVE-2019-14666
GHSA-47HQ-PFRR-JH5Q

Affected Products

Alt Linux
Glpi