CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
42.8%
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.
Vendor | Product | Version | CPE |
---|---|---|---|
dolibarr | dolibarr | * | cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:* |
dolibarr | dolibarr_erp\/crm | 3.3.0 | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:3.3.0:beta1:*:*:*:*:*:* |
dolibarr | dolibarr_erp\/crm | 3.3.0 | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:3.3.0:beta2:*:*:*:*:*:* |
[
{
"product": "dolibarr",
"vendor": "Dolibarr",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "3.3.beta1_20121221",
"versionType": "custom"
}
]
}
]
More
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
42.8%