First published: Sun Jan 26 2020(Updated: )
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =10.0.6 | |
composer/dolibarr/dolibarr | =10.0.6 | |
=10.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7995 is a vulnerability in Dolibarr 10.0.6 that allows an unlimited rate of failed authentication attempts on the login page.
CVE-2020-7995 has a severity rating of 9.8, which is considered critical.
The affected software is Dolibarr 10.0.6.
The CWE for CVE-2020-7995 is 307, which relates to insufficient protection against brute force attacks.
Yes, here are some references related to CVE-2020-7995: [PacketStormSecurity](http://packetstormsecurity.com/files/163541/Dolibarr-ERP-CRM-10.0.6-Login-Brute-Forcer.html), [GitHub](https://github.com/tufangungor/tufangungor.github.io/blob/master/_posts/2020-01-19-dolibarr-10.0.6-brute-force.md), [Exploit](https://tufangungor.github.io/exploit/2020/01/18/dolibarr-10.0.6-brute-force.html)