Cross-Site Request Forgery (CSRF) in dolibarr/dolibarr

Valid

Reported on

Jul 21st 2021


✍️ Description

CSRF bug to set-paid expense-report

🕵️‍♂️ Proof of Concept

Here it does not check token parameter for csrf .You can remove token paramater from url. bellow request is vulnerable to csrf attack when set-paid expense report.
https://demo.dolibarr.org/expensereport/card.php?id=119&action=set_paid

💥 Impact

csrf attack

We have contacted a member of the dolibarr team and are waiting to hear back 4 months ago
Laurent Destailleur validated this vulnerability 2 months ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Laurent Destailleur confirmed that a fix has been merged on b46f40 2 months ago
Laurent Destailleur has been awarded the fix bounty