Improper Authentication in dolibarr - CVE-2017-8879

 

Improper Authentication in dolibarr - CVE-2017-8879

Published: May 10, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39061
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8879
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.


Affected software

dolibarr

How to mitigate CVE-2017-8879

Install update from vendor's website.


External References

Related Security Bulletins