// For flags

CVE-2019-15062

 

Severity Score

8.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

Se descubrió un problema en Dolibarr versión 11.0.0-alpha. Un usuario puede almacenar un elemento IFRAME (que contiene una petición de tipo CSRF del archivo user/card.php) en su página de configuración Linked Files. Cuando es visitada por el administrador, este podría tomar el control completamente de la cuenta de administrador. (El mecanismo de protección para CSRF es comprobar el encabezado Referer; sin embargo, debido a que el ataque proviene de una de las páginas de configuración de la aplicación, este mecanismo es omitido).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-08-14 CVE Reserved
  • 2019-08-14 CVE Published
  • 2023-05-01 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dolibarr
Search vendor "Dolibarr"
Dolibarr Erp\/crm
Search vendor "Dolibarr" for product "Dolibarr Erp\/crm"
11.0.0
Search vendor "Dolibarr" for product "Dolibarr Erp\/crm" and version "11.0.0"
alpha
Affected