CVE-2021-25957
Status: ModifiedHigh (8.8)—
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.06%
- Percentile among all scored CVEs: 63
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-640
- CWE-640
References
- https://github.com/Dolibarr/dolibarr/commit/87f9530272925f0d651f59337a35661faeb6f377
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25957
- https://github.com/Dolibarr/dolibarr/commit/87f9530272925f0d651f59337a35661faeb6f377
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25957
Raw JSON (NVD)
Show
{
"id": "CVE-2021-25957",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vulnerabilitylab@mend.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vulnerabilitylab@mend.io",
"affectedData": [
{
"vendor": "Dolibarr",
"product": "dolibarr",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "2.8.1",
"status": "affected"
}
],
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "13.0.2"
}
]
}
]
}
],
"published": "2021-08-17T15:15:08.040",
"references": [
{
"url": "https://github.com/Dolibarr/dolibarr/commit/87f9530272925f0d651f59337a35661faeb6f377",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25957",
"tags": [
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://github.com/Dolibarr/dolibarr/commit/87f9530272925f0d651f59337a35661faeb6f377",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25957",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnerabilitylab@mend.io",
"description": [
{
"lang": "en",
"value": "CWE-640"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-640"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password."
},
{
"lang": "es",
"value": "En la aplicación \"Dolibarr\", versiones v2.8.1 a v13.0.2, son vulnerables a la toma de cuenta por medio de la funcionalidad password reset. Un atacante poco privilegiado puede restablecer la contraseña de cualquier usuario de la aplicación usando el enlace de restablecimiento de contraseña que el usuario recibió mediante correo electrónico cuando se le solicitó una contraseña olvidada."
}
],
"lastModified": "2026-06-17T03:42:40.493",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "730BE634-E4DD-4AC7-89A0-74ED7ED1EB2D",
"versionEndIncluding": "13.0.2",
"versionStartIncluding": "2.8.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnerabilitylab@mend.io"
}