#VU21428 Cross-site request forgery in dolibarr - CVE-2019-1010054
Published: September 30, 2019
dolibarr
Dolibarr ERP & CRM
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in "dolibarr/user/card.php" and "dolibarr/admin/security.php" URLs. A remote attacker can trick the victim to visit a specially crafted web page and change user password, disable users and disable password encryptation.