Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dolibarr_erp/crm | Dolibarr | 4.0.4 (including) | 4.0.4 (including) |
Dolibarr | Ubuntu | artful | * |
Dolibarr | Ubuntu | esm-apps/xenial | * |
Dolibarr | Ubuntu | trusty | * |
Dolibarr | Ubuntu | xenial | * |
Dolibarr | Ubuntu | yakkety | * |
Dolibarr | Ubuntu | zesty | * |