CVE-2019-1010054 Information
Description
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password disable users and disable password encryptation. The component is: Function User password change user disable and password encryptation. The attack vector is: admin access malitious urls.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://github.com/lucasgcilento/CVE/blob/master/Dolibarr_CSRF Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password disable users and disable password encryptation. The component is: Function User password change user disable and password encryptation. The attack vector is: admin access malitious urls.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: