Moderate severityNVD Advisory· Published Aug 9, 2021· Updated Sep 17, 2024
Improper Access Control in “Dolibarr”
CVE-2021-25954
Description
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | >= 2.8.1, < 14.0.0 | 14.0.0 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-vxhc-c4qm-647pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-25954ghsaADVISORY
- github.com/Dolibarr/dolibarr/commit/8cc100012d46282799fb19f735a53b7101569377ghsax_refsource_MISCWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25954ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.