PT-2021-16880 · Dolibarr · Dolibarr

Daniel Elkabes

·

Published

2021-08-17

·

Updated

2025-04-03

·

CVE-2021-25956

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr versions 3.3.beta1 20121221 through 13.0.2
Description The issue allows admin level users to change other user's details but fails to validate already existing Login name, while renaming the user Login. This leads to complete account takeover of the victim user, as the password gets overwritten for the victim user having a similar login name.
Recommendations For versions 3.3.beta1 20121221 through 13.0.2, consider disabling the Modify access for admin level users to change other user's details until a patch is available, or restrict the ability to rename user Login to prevent account takeover. Additionally, monitor user account activity for suspicious changes to login names and passwords.

Fix

Improper Authentication

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2021-25956
CVE-2021-25956
GHSA-FJQG-W8G6-HHQ8

Affected Products

Dolibarr