Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw7v-qrhc-jjg2

Опубликовано: 01 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Access Control vulnerability in Dolibarr

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.1, in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

< 14.0.1

14.0.1

EPSS

Процентиль: 56%
0.00338
Низкий

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

CVSS3: 7.5
nvd
больше 3 лет назад

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

CVSS3: 7.5
debian
больше 3 лет назад

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fix ...

EPSS

Процентиль: 56%
0.00338
Низкий

7.5 High

CVSS3

Дефекты

CWE-863