SB2019071814 - Cross-site request forgery in Dolibarr
Published: July 18, 2019 Updated: September 30, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2019-1010054)
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in "dolibarr/user/card.php" and "dolibarr/admin/security.php" URLs. A remote attacker can trick the victim to visit a specially crafted web page and change user password, disable users and disable password encryptation.
Remediation
Install update from vendor's website.