Description
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2002-0559)
WordPress Plugin Count per Day Multiple Vulnerabilities (3.5.6)
MySQL CVE-2019-2963 Vulnerability (CVE-2019-2963)
WordPress Plugin Store Locator Plus for WordPress Multiple Vulnerabilities (3.0.1)
WordPress Plugin Product Catalog Cross-Site Scripting (4.2.8)