Improper Access Control in “Dolibarr”
Vulnerability Description
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25954
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Hagai Wechsler
References
More from Dolibarr
View All →Affected Vendor
Dolibarr
View all reports →