Description
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4229 | Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls. |
Github GHSA |
GHSA-hwmc-v6j6-gc2p | Dolibarr Cross Site Request Forgery (CSRF) |
References
History
No history.
Status: PUBLISHED
Assigner: dwf
Published:
Updated: 2024-08-05T03:07:18.176Z
Reserved: 2019-03-20T00:00:00.000Z
Link: CVE-2019-1010054
No data.
Status : Modified
Published: 2019-07-18T13:15:11.063
Modified: 2024-11-21T04:17:56.820
Link: CVE-2019-1010054
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA