CVE-2021-25957
- EPSS 0.33%
- Veröffentlicht 17.08.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through ...
CVE-2021-25956
- EPSS 0.37%
- Veröffentlicht 17.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account t...
- EPSS 0.42%
- Veröffentlicht 15.08.2021 21:15:06
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. The...
CVE-2021-25954
- EPSS 0.17%
- Veröffentlicht 09.08.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field...
CVE-2020-14209
- EPSS 10.17%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:52
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control ...
CVE-2020-14201
- EPSS 0.15%
- Veröffentlicht 21.08.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:51
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
CVE-2020-14443
- EPSS 0.3%
- Veröffentlicht 18.06.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:03:17
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
CVE-2020-13094
- EPSS 1.71%
- Veröffentlicht 18.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:39
Dolibarr before 11.0.4 allows XSS.
CVE-2020-12669
- EPSS 0.29%
- Veröffentlicht 06.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:02
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
CVE-2019-19212
- EPSS 1.15%
- Veröffentlicht 16.03.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:20
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).