Описание
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
Уязвимые конфигурации
Конфигурация 1Версия до 20.0.2 (исключая)
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 16%
0.00051
Низкий
4.3 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-285
CWE-639
Связанные уязвимости
CVSS3: 4.3
ubuntu
около 1 года назад
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
CVSS3: 4.3
debian
около 1 года назад
An Improper Authorization vulnerability exists in Dolibarr versions pr ...
EPSS
Процентиль: 16%
0.00051
Низкий
4.3 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-285
CWE-639