PT-2026-81006 · Dolibarr · Dolibarr
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dolibarr versions prior to 24.0.0
Description
A sensitive data exposure issue exists in the Members REST API. Authenticated attackers with member-read permissions can retrieve bcrypt password verifiers by querying member endpoints. This occurs because the base API serializer and the Members API class fail to filter crypted password verifier fields when calling individual member or member list endpoints, which could facilitate offline password cracking attacks.
Recommendations
Update to version 24.0.0 or later.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolibarr