PT-2020-19906 · Dolibarr · Dolibarr
CVE-2020-7995
·
Published
2020-01-26
·
Updated
2025-04-03
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dolibarr version 10.0.6
Description
The issue concerns the htdocs/index.php?mainmenu=home login page, which allows an unlimited rate of failed authentication attempts. This could potentially lead to brute-force attacks.
Recommendations
For Dolibarr version 10.0.6, consider implementing rate limiting on the login page to restrict the number of failed authentication attempts. As a temporary workaround, restrict access to the
htdocs/index.php?mainmenu=home login page until a patch is available.Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dolibarr