In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
References
Link Resource
https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.html Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-16T19:03:47

Updated: 2020-04-16T19:03:47

Reserved: 2020-04-16T00:00:00


Link: CVE-2020-11825

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-16T19:15:27.637

Modified: 2022-11-17T17:21:59.260


Link: CVE-2020-11825

JSON object: View

cve-icon Redhat Information

No data.

CWE