Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjqg-w8g6-hhq8

Опубликовано: 02 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Dolibarr vulnerable to Improper Authentication and Improper Access Control

In Dolibarr application, v3.3.beta1_20121221 to v13.0.2 have Modify access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user Login. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

>= 3.3.beta1, < 13.0.2

14.0.0

EPSS

Процентиль: 58%
0.00372
Низкий

7.2 High

CVSS3

Дефекты

CWE-284
CWE-287

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 4 лет назад

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVSS3: 4.7
nvd
больше 4 лет назад

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVSS3: 4.7
debian
больше 4 лет назад

In \u201cDolibarr\u201d application, v3.3.beta1_20121221 to v13.0.2 ha ...

EPSS

Процентиль: 58%
0.00372
Низкий

7.2 High

CVSS3

Дефекты

CWE-284
CWE-287