Improper Authentication in dolibarr - CVE-2017-8879
Published: May 10, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU39061
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8879
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local non-authenticated attacker to execute arbitrary code.
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
Affected software
dolibarr
How to mitigate CVE-2017-8879
Install update from vendor's website.