CVE-2020-11825

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
References
Link Resource
https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.6:*:*:*:*:*:*:*

History

17 Nov 2022, 17:21

Type Values Removed Values Added
CPE cpe:2.3:a:dolibarr:dolibarr:10.0.6:*:*:*:*:*:*:* cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.6:*:*:*:*:*:*:*
First Time Dolibarr dolibarr Erp\/crm

Information

Published : 2020-04-16 19:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-11825

Mitre link : CVE-2020-11825

CVE.ORG link : CVE-2020-11825


JSON object : View

Products Affected

dolibarr

  • dolibarr_erp\/crm
CWE
CWE-352

Cross-Site Request Forgery (CSRF)