CVE-2024-31503: CSRF
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31503?
CVE-2024-31503 has been rated as a high severity vulnerability due to potential account takeover risks.
How do I fix CVE-2024-31503?
To mitigate CVE-2024-31503, upgrade to Dolibarr ERP CRM version 19.0.1 or later.
Who is affected by CVE-2024-31503?
CVE-2024-31503 affects all authenticated users of Dolibarr ERP CRM versions 19.0.0 and earlier.
What are the potential impacts of CVE-2024-31503?
The potential impacts of CVE-2024-31503 include the theft of session cookies and CSRF protection tokens, leading to account loss.
What causes CVE-2024-31503?
CVE-2024-31503 is caused by incorrect access control allowing attackers to exploit user interactions with compromised web pages.