PT-2022-10655 · Unknown · Dolibarr Erp/Crm

Published

2022-03-31

·

Updated

2025-04-03

·

CVE-2021-37517

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP/CRM versions 13.0.2 through 13.0.2
Description An Access Control issue exists in the forgot-password function because the application allows email addresses as usernames, which can cause a Denial of Service. The issue is related to the forgot-password function.
Recommendations For Dolibarr ERP/CRM version 13.0.2, update to version 14.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the forgot-password function until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2021-37517
CVE-2021-37517
GHSA-XW7V-QRHC-JJG2

Affected Products

Dolibarr Erp/Crm