{"id":"CVE-2019-13240","details":"An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.","modified":"2026-08-07T14:49:50.222951Z","published":"2019-07-10T14:15:11.793Z","references":[{"type":"ADVISORY","url":"https://github.com/glpi-project/glpi/releases/tag/9.4.1"},{"type":"FIX","url":"https://github.com/glpi-project/glpi/commit/5da9f99b2d81713b1e36016b47ce656a33648bc7"},{"type":"FIX","url":"https://github.com/glpi-project/glpi/commit/86a43ae47b3dd844947f40a2ffcf1a36e53dbba6"},{"type":"FIX","url":"https://github.com/glpi-project/glpi/compare/1783b78...8e621f6"},{"type":"EVIDENCE","url":"https://www.synacktiv.com/ressources/advisories/GLPI_9.4.0_unsafe_reset.pdf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/glpi-project/glpi","events":[{"introduced":"0"},{"fixed":"8e621f6ce937eea6b7f1412a65c6dd74af188706"},{"fixed":"5da9f99b2d81713b1e36016b47ce656a33648bc7"},{"fixed":"86a43ae47b3dd844947f40a2ffcf1a36e53dbba6"}],"database_specific":{"cpe":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"9.4.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["9.4.0","9.4.0-rc2","9.4.0-rc1","9.4.0-beta","9.3-beta","9.1","9.1-RC2","9.1-RC1","0.90","0.90-RC2","0.90-RC1","0.90-beta2","0.90-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13240.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}