Description
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.
Remediation
References
Related Vulnerabilities
WordPress Plugin Post Pay Counter PHP Object Injection (2.730)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2011-2526)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.38)
PHP Other Vulnerability (CVE-2015-1352)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-3327)