Логотип exploitDog
bind:CVE-2021-25956
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25956

Количество 4

Количество 4

ubuntu логотип

CVE-2021-25956

больше 4 лет назад

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2021-25956

больше 4 лет назад

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2021-25956

больше 4 лет назад

In \u201cDolibarr\u201d application, v3.3.beta1_20121221 to v13.0.2 ha ...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-fjqg-w8g6-hhq8

больше 4 лет назад

Dolibarr vulnerable to Improper Authentication and Improper Access Control

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-25956

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-25956

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-25956

In \u201cDolibarr\u201d application, v3.3.beta1_20121221 to v13.0.2 ha ...

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-fjqg-w8g6-hhq8

Dolibarr vulnerable to Improper Authentication and Improper Access Control

CVSS3: 7.2
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу