CVE-2019-1010054: CSRF
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010054?
CVE-2019-1010054 is considered to be a critical vulnerability due to its potential to allow malicious actions such as changing user passwords and disabling accounts.
How do I fix CVE-2019-1010054?
To mitigate CVE-2019-1010054, it is advised to upgrade Dolibarr to a version higher than 7.0.0 where the vulnerability has been patched.
What components are affected by CVE-2019-1010054?
CVE-2019-1010054 affects the user password change functionality, user disablement feature, and password encryption processes within Dolibarr.
What are the potential impacts of CVE-2019-1010054?
Exploitation of CVE-2019-1010054 could allow an attacker to change user passwords, disable users, and potentially compromise password encryption.
Who is vulnerable to CVE-2019-1010054?
Any administrator using Dolibarr version 7.0.0 is vulnerable to CVE-2019-1010054, as the attack requires admin access.