DayByDay CRM - Missing Authorization when Viewing Absences
Vulnerability Description
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22108
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- WhiteSource Vulnerability Research Team (WVR)
References
More from Bottelet
View All →Affected Vendor
Bottelet
View all reports →