Medium severity4.3NVD Advisory· Published Aug 9, 2021· Updated Jun 17, 2026
CVE-2021-25954
CVE-2021-25954
Description
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | >= 2.8.1, < 14.0.0 | 14.0.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/Dolibarr/dolibarr/commit/8cc100012d46282799fb19f735a53b7101569377nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vxhc-c4qm-647pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-25954ghsaADVISORY
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25954nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.