In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
References
Link | Resource |
---|---|
https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.html | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-04-16 12:15
Updated : 2022-11-17 09:21
NVD link : CVE-2020-11825
Mitre link : CVE-2020-11825
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
dolibarr
- dolibarr_erp\/crm