VYPR
Medium severity4.3NVD Advisory· Published Aug 9, 2021· Updated Jun 17, 2026

CVE-2021-25954

CVE-2021-25954

Description

In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
dolibarr/dolibarrPackagist
>= 2.8.1, < 14.0.014.0.0

Affected products

3
  • Dolibarr/Dolibarr2 versions
    cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*range: >=2.8.1,<=13.0.4
    • (no CPE)range: 2.8.1
  • ghsa-coords
    Range: >= 2.8.1, < 14.0.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.