Cross-Site Request Forgery (CSRF) in dolibarr/dolibarr


Reported on

Jul 21st 2021

✍️ Description

CSRF bug to remove linked file

🕵️‍♂️ Proof of Concept

bellow request is vulnerable to csrf attack when removing linked file.

💥 Impact

csrf attack

We have contacted a member of the dolibarr team and are waiting to hear back a year ago
ranjit-git modified the report
a year ago
Laurent Destailleur confirmed that a fix has been merged on c3e885 a year ago
Laurent Destailleur has been awarded the fix bounty
card.php#L70-L150 has been validated
to join this conversation