CVE Vulnerabilities

CVE-2021-25956

Published: Aug 17, 2021 | Modified: Nov 17, 2022
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

Affected Software

Name Vendor Start Version End Version
Dolibarr Dolibarr 3.3.1 (including) 13.0.2 (including)
Dolibarr_erp/crm Dolibarr 3.3.0-beta1 (including) 3.3.0-beta1 (including)
Dolibarr_erp/crm Dolibarr 3.3.0-beta2 (including) 3.3.0-beta2 (including)
Dolibarr Ubuntu esm-apps/xenial *
Dolibarr Ubuntu trusty *
Dolibarr Ubuntu xenial *

References