Medium severity4.3NVD Advisory· Published Nov 15, 2024· Updated Jun 17, 2026
CVE-2021-3991
CVE-2021-3991
Description
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | < 15.0.0 | 15.0.0 |
Affected products
4- osv-coords2 versions
< 20.0.2+ 1 more
- (no CPE)range: < 20.0.2
- (no CPE)range: < 15.0.0
Patches
Vulnerability mechanics
References
4- github.com/dolibarr/dolibarr/commit/63cd06394f39d60784d6e6a0ccf4867a71a6568fnvdPatchWEB
- github.com/advisories/GHSA-wppr-j57c-8jpmghsaADVISORY
- huntr.com/bounties/58ddbd8a-0faf-4b3f-aec9-5850bb19ab67nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-3991ghsaADVISORY
News mentions
0No linked articles in our index yet.