CVE-2017-8879

MEDIUM

Dolibarr ERP/CRM <4.0.4 - Info Disclosure

Title source: llm

Description

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

Scores

CVSS v3 6.8
EPSS 0.0005
EPSS Percentile 14.7%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (3)
dolibarr/dolibarr_erp\/crm
dolibarr/dolibarr Packagist
n/a/n/a
Published May 10, 2017
Tracked Since Feb 18, 2026