ZeroHour

CVE-2020-11825

PoC
CVSS 3.1
8.8 high
EPSS
1%p61
Published
()
Modified
Description

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

Vendors
dolibarr
Products
dolibarr erp\/crm
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.