Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m66x-wm27-xxpc

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Dolibarr Cross-Site Request Forgery Vulnerability

In Dolibarr 10.0.6, forms are protected with a Cross-Site Request Forgery (CSRF) token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

<= 10.0.6

Отсутствует

EPSS

Процентиль: 42%
0.00197
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

CVSS3: 8.8
nvd
почти 6 лет назад

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

CVSS3: 8.8
debian
почти 6 лет назад

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF ...

EPSS

Процентиль: 42%
0.00197
Низкий

8.8 High

CVSS3

Дефекты

CWE-352