Vulnerability Description
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | 10.0.6 |
Related Weaknesses (CWE)
References
- https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.htmlExploitThird Party Advisory
- https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-11825?
CVE-2020-11825 is a vulnerability with a CVSS score of 8.8 (HIGH). In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be val...
How severe is CVE-2020-11825?
CVE-2020-11825 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11825?
Check the references section above for vendor advisories and patch information. Affected products include: Dolibarr Dolibarr Erp\/Crm.