I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.6"
},
{
"introduced": "0"
},
{
"last_affected": "4.7"
}
]
}