PT-2017-18601 · Dolibarr · Dolibarr Erp/Crm

Published

2017-05-10

·

Updated

2022-11-17

·

CVE-2017-8879

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP/CRM version 4.0.4
Description The issue allows password changes without requiring the current password, making it easier for attackers with physical access to obtain access via an unattended workstation.
Recommendations For Dolibarr ERP/CRM version 4.0.4, consider implementing a workaround that requires the current password for password changes until a patch is available. As a temporary mitigation measure, restrict access to workstations with active sessions to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2017-8879
GHSA-5X4J-XCMV-V3Q2

Affected Products

Dolibarr Erp/Crm