CVE-2020-11825
HIGHCVSS 8.8/10EPSS 0.99%
Last modified
CVE-2020-11825 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | 10.0.6 |
References
- https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.htmlExploit, Third Party Advisory
- https://fatihhcelik.blogspot.com/2020/04/dolibarr-csrf.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11825?
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
How severe is CVE-2020-11825?
CVE-2020-11825 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.99% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11825?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-11819In Rukovoditel 2.5.2, an attacker may inject an arbitrary .p…9.8
- CVE-2020-1182A remote code execution vulnerability exists in Microsoft Dy…7.3
- CVE-2020-11820Rukovoditel 2.5.2 is affected by a SQL injection vulnerabili…9.8
- CVE-2020-11821In Rukovoditel 2.5.2, users' passwords and usernames are sto…5.3
- CVE-2020-11822In Rukovoditel 2.5.2, there is a stored XSS vulnerability on…6.1
- CVE-2020-11823In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is…5.4
- CVE-2020-11826Users can lock their notes with a password in Memono version…7.5
- CVE-2020-11827In GOG Galaxy 1.2.67, there is a service that is vulnerable …7.8
- CVE-2020-11828In ColorOS (oppo mobile phone operating system, based on AOS…7.5
- CVE-2020-11829Dynamic loading of services in the backup and restore SDK le…9.8
- CVE-2020-1183A cross-site-scripting (XSS) vulnerability exists when Micro…5.4
- CVE-2020-11830QualityProtect has a vulnerability to execute arbitrary syst…9.8
Are you affected by CVE-2020-11825?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
