← Volver a CVEs
CVE-2020-11825
HIGH8.8
Descripcion
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado4/16/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
dolibarr:dolibarr_erp\/crm
Debilidades (CWE)
CWE-352
Referencias
https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.html(cve@mitre.org)
https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.