-
CVSS Score
-The vulnerability explicitly affects the htdocs/index.php?mainmenu=home endpoint. While the exact function name isn't provided in available resources, the core issue resides in the authentication flow handled by this entry point. The absence of: 1) Failed attempt counters, 2) IP-based rate limiting, and 3) Account lockout mechanisms in the authentication handler makes this function vulnerable. The high confidence comes from the direct correlation between the described vulnerability (unlimited auth attempts) and the fundamental authentication processing logic that would need to implement these missing protections.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dolibarr/dolibarr | composer | = 10.0.6 |