Логотип exploitDog
bind:CVE-2019-14666
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-14666

Количество 4

Количество 4

ubuntu логотип

CVE-2019-14666

больше 6 лет назад

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-14666

больше 6 лет назад

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-14666

больше 6 лет назад

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/au ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-f2c5-q3w6-4h6j

больше 3 лет назад

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-14666

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14666

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-14666

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/au ...

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
github логотип
GHSA-f2c5-q3w6-4h6j

GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу