PT-2017-18601 · Dolibarr · Dolibarr Erp/Crm

CVE-2017-8879

·

Publicado

2017-05-10

·

Atualizado

2022-11-17

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP/CRM version 4.0.4
Description The issue allows password changes without requiring the current password, making it easier for attackers with physical access to obtain access via an unattended workstation.
Recommendations For Dolibarr ERP/CRM version 4.0.4, consider implementing a workaround that requires the current password for password changes until a patch is available. As a temporary mitigation measure, restrict access to workstations with active sessions to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8879
GHSA-5X4J-XCMV-V3Q2

Produtos afetados

Dolibarr Erp/Crm