Weak Password Recovery Mechanism for Forgotten Password
High severity
GitHub Reviewed
Published
Sep 2, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Aug 17, 2021
Reviewed
Aug 19, 2021
Published to the GitHub Advisory Database
Sep 2, 2021
Last updated
Feb 1, 2023
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.
References