CVE-2019-15062
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)
Se descubrió un problema en Dolibarr versión 11.0.0-alpha. Un usuario puede almacenar un elemento IFRAME (que contiene una petición de tipo CSRF del archivo user/card.php) en su página de configuración Linked Files. Cuando es visitada por el administrador, este podría tomar el control completamente de la cuenta de administrador. (El mecanismo de protección para CSRF es comprobar el encabezado Referer; sin embargo, debido a que el ataque proviene de una de las páginas de configuración de la aplicación, este mecanismo es omitido).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-14 CVE Reserved
- 2019-08-14 CVE Published
- 2023-05-01 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://gauravnarwani.com/publications/CVE-2019-15062 | 2024-08-05 | |
https://github.com/Dolibarr/dolibarr/issues/11671 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dolibarr Search vendor "Dolibarr" | Dolibarr Erp\/crm Search vendor "Dolibarr" for product "Dolibarr Erp\/crm" | 11.0.0 Search vendor "Dolibarr" for product "Dolibarr Erp\/crm" and version "11.0.0" | alpha |
Affected
|