Dolibarr vulnerable to Improper Authentication and Improper Access Control
High severity
GitHub Reviewed
Published
Sep 2, 2021
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Package
Affected versions
>= 3.3.beta1, < 13.0.2
Patched versions
14.0.0
Description
Published by the National Vulnerability Database
Aug 17, 2021
Reviewed
Aug 26, 2021
Published to the GitHub Advisory Database
Sep 2, 2021
Last updated
Jan 29, 2023
In
Dolibarr
application, v3.3.beta1_20121221 to v13.0.2 haveModify
access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the userLogin
. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.References