Lucene search

K
osvGoogleOSV:GHSA-HWMC-V6J6-GC2P
HistoryMay 24, 2022 - 4:50 p.m.

Dolibarr Cross Site Request Forgery (CSRF)

2022-05-2416:50:37
Google
osv.dev
2
dolibarr 7.0.0
cross site request forgery
password change
user disable
password encryption
admin access

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

44.9%

Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

44.9%