CVE-2021-37517: High severity dolibarr erp & crm vulnerability
Published Mar 31, 2022
·Updated
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
Affected Software
1 affected component
dolibarr Dolibarr Erp\/crm=13.0.2
Remediation
Event History
Mar 31, 2022
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-37517?
The severity of CVE-2021-37517 is high with a score of 7.5.
2
What is the vulnerability in Dolibarr ERP/CRM 13.0.2?
The vulnerability in Dolibarr ERP/CRM 13.0.2 is an Access Control vulnerability.
3
How can the Access Control vulnerability be exploited?
The Access Control vulnerability can be exploited in the forgot-password function by using email addresses as usernames, leading to a Denial of Service.
4
What is the fixed version for Dolibarr ERP/CRM?
The fixed version for Dolibarr ERP/CRM is 14.0.0.
5
How do I fix the Access Control vulnerability in Dolibarr ERP/CRM?
To fix the Access Control vulnerability in Dolibarr ERP/CRM, update to version 14.0.0.