
Cloud Vulnerability DB
A community-led vulnerabilities database
In Dolibarr application versions 2.8.1 to 13.0.2, a vulnerability was discovered that allows unauthorized password resets. The vulnerability was disclosed on August 17, 2021, and affects the password recovery mechanism of the application. This security flaw enables a low-privileged user to potentially take over other user accounts through the password reset functionality (WhiteSource DB).
The vulnerability is classified as CWE-640 (Weak Password Recovery Mechanism for Forgotten Password) with a CVSS v3.1 base score of 8.8 (High). The attack vector is network-based with low attack complexity, requiring low privileges and no user interaction. The scope is unchanged, but the impact affects confidentiality, integrity, and availability at high levels. The vulnerability stems from improper validation of username parameters in the password reset functionality (WhiteSource DB).
The vulnerability allows complete account takeover of victim users. When exploited, an attacker can reset and overwrite passwords for other users in the system, potentially gaining unauthorized access to administrator accounts. This could lead to unauthorized access to sensitive information and system controls (WhiteSource DB).
The vulnerability has been fixed in version 14.0.0 of the Dolibarr application. The fix includes proper validation of the username parameter in the password reset functionality, as evidenced by the commit that addresses the issue (GitHub Commit). Organizations using affected versions should upgrade to version 14.0.0 or later to mitigate this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."