CVE-2019-15062

Source
https://cve.org/CVERecord?id=CVE-2019-15062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-15062
Aliases
Downstream
Published
2019-08-14T23:15:10.437Z
Modified
2026-03-14T09:34:02.051361Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15062.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.0.0-alpha"
            }
        ]
    }
]