Improper Authorization Vulnerability in Dolibarr
CVE-2021-3991
4.3MEDIUM
Key Information
- Vendor
- Dolibarr
- Status
- Dolibarr/dolibarr
- Vendor
- CVE Published:
- 15 November 2024
Summary
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
Affected Version(s)
dolibarr/dolibarr < unspecified
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Risk change from: null to: 4.3 - (MEDIUM)
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database