CVE-2017-8879
MEDIUMDolibarr ERP/CRM <4.0.4 - Info Disclosure
Title source: llmDescription
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
Scores
CVSS v3
6.8
EPSS
0.0005
EPSS Percentile
14.7%
Attack Vector
PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (3)
dolibarr/dolibarr_erp\/crm
dolibarr/dolibarr
Packagist
n/a/n/a
Published
May 10, 2017
Tracked Since
Feb 18, 2026