CVE-2019-15062
Dolibarr Cross-Site Request Forgery (CSRF)
8.0
HIGH
CVSS 3.1
EPSS 0.61%
描述
An issue was discovered in Dolibarr. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)
如何修補 CVE-2019-15062
要修補 CVE-2019-15062,請將受影響套件升級到下列已修補版本。
- —升級至 10.0.2 或更新版本
CVE-2019-15062 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 10.0, < 10.0.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |