Improper access control in GLPI - CVE-2019-14666
Published: September 24, 2019 / Updated: May 4, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the autocompletion feature when handling autocomplete requests. A remote user can use an unprivileged account to retrieve sensitive data from other users to disclose sensitive information.