Improper Access Control in Dolibarr
Moderate severity
GitHub Reviewed
Published
Aug 11, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Aug 9, 2021
Reviewed
Aug 10, 2021
Published to the GitHub Advisory Database
Aug 11, 2021
Last updated
Feb 1, 2023
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
References