Описание
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
Ссылки
- ExploitMitigationThird Party Advisory
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:4.0.4:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00048
Низкий
6.8 Medium
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 6.8
ubuntu
больше 8 лет назад
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
CVSS3: 6.8
debian
больше 8 лет назад
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the c ...
CVSS3: 6.8
github
больше 3 лет назад
Dolibarr allows password changes without supplying the current password
EPSS
Процентиль: 15%
0.00048
Низкий
6.8 Medium
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287