PT-2024-24124 · Unknown · Dolibarr Erp/Crm
Arthur Valverde M
+1
·
Published
2024-04-16
·
Updated
2025-06-14
·
CVE-2024-31503
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Dolibarr ERP CRM versions 19.0.0 and before
Description
The issue allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover. This occurs due to incorrect access control in the software.
Recommendations
For versions 19.0.0 and before, update to a version that includes the necessary access control fixes to prevent session cookie and CSRF token theft.
As a temporary workaround, consider restricting user interaction with crafted web pages to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dolibarr Erp/Crm