CVE-2017-8879

MEDIUM6.8EPSS 0.05%

Dolibarr allows password changes without supplying the current password

Published: 5/13/2022Modified: 4/24/2024
Also known as:GHSA-5x4j-xcmv-v3q2

Description

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.8CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (3)