First published: Wed May 10 2017(Updated: )
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | =4.0.4 | |
Dolibarr ERP & CRM | =4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8879 is considered a moderate severity vulnerability due to the potential for unauthorized password changes.
To fix CVE-2017-8879, upgrade to a patched version of Dolibarr ERP/CRM beyond 4.0.4 that requires the current password for changes.
CVE-2017-8879 affects users of Dolibarr ERP/CRM version 4.0.4, especially in environments where workstations may be left unattended.
An attacker with physical access to an unattended workstation could change the password without knowing the current one, gaining unauthorized access.
Yes, CVE-2017-8879 has been addressed in versions of Dolibarr ERP/CRM released after 4.0.4.