Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qq9-qg7j-fcm9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Dolibarr Cross-Site Request Forgery (CSRF)

An issue was discovered in Dolibarr. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

>= 10.0, < 10.0.2

10.0.2

EPSS

Процентиль: 32%
0.00122
Низкий

8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8
ubuntu
больше 6 лет назад

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

CVSS3: 8
nvd
больше 6 лет назад

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

CVSS3: 8
debian
больше 6 лет назад

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an ...

EPSS

Процентиль: 32%
0.00122
Низкий

8 High

CVSS3

Дефекты

CWE-352