First published: Thu Mar 31 2022(Updated: )
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr ERP & CRM | =13.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-37517 is high with a score of 7.5.
The vulnerability in Dolibarr ERP/CRM 13.0.2 is an Access Control vulnerability.
The Access Control vulnerability can be exploited in the forgot-password function by using email addresses as usernames, leading to a Denial of Service.
The fixed version for Dolibarr ERP/CRM is 14.0.0.
To fix the Access Control vulnerability in Dolibarr ERP/CRM, update to version 14.0.0.