CVE-2017-8879 dolibarr

Metadata

medium
4.6
dolibarr
CVE-2017-8879
2017-07-05 05:03
CVE-2017-8879
2017-06-30 17:03
2017-06-18 07:52
2017-06-16 19:23
2017-05-17 05:03
2017-05-12 05:03
2017-05-10 23:56

Description

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
buster dolibarr 5.0.4+dfsg3-1
jessie dolibarr None
sid dolibarr 5.0.4+dfsg3-1
stretch dolibarr None