High severity7.5NVD Advisory· Published Apr 17, 2024· Updated Jun 17, 2026
CVE-2024-31503
CVE-2024-31503
Description
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | <= 19.0.0 | — |
Affected products
4- ghsa-coords2 versions
<= 19.0.0+ 1 more
- (no CPE)range: <= 19.0.0
- (no CPE)range: < 19.0.1
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-6ppg-rgrg-f573ghsaADVISORY
- github.com/alexbsec/CVEs/blob/master/2024/CVE-2024-31503.mdnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-31503ghsaADVISORY
News mentions
0No linked articles in our index yet.