GHSA-fjqg-w8g6-hhq8
Dashboard / Vulnerabilities / GHSA-fjqg-w8g6-hhq8
GHSA-fjqg-w8g6-hhq8
Summary: Dolibarr vulnerable to Improper Authentication and Improper Access Control
Details: In `Dolibarr` application, v3.3.beta1_20121221 to v13.0.2 have `Modify` access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user `Login`. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-25956, https://github.com/Dolibarr/dolibarr/commit/c4cba43bade736ab89e31013a6ccee59a6e077ee, https://github.com/Dolibarr/dolibarr, https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25956
Affected packages
Package
Name: dolibarr/dolibarr
Purl: pkg:composer/dolibarr/dolibarr
Affected ranges
Type: ECOSYSTEM
Events:
