Skip to content

Account takeover vulnerability

High
trasher published GHSA-47hq-pfrr-jh5q Sep 24, 2019 · 1 comment

Package

No package listed

Affected versions

<9.4.3

Patched versions

9.4.4

Description

Impact

It was possible to abuse autocompletion feature to retrieve sensitive data from any user, using an unprivileged account.

Patches

Issue has been fixes in GLPI 9.4.4; upgrading is highly recommended.

Severity

High

CVE ID

CVE-2019-14666

Weaknesses

No CWEs