ZeroHour

CVE-2021-3991

CVSS 3.1
4.3 medium
EPSS
<1%p24
Published
()
Modified
Description

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

Vendors
dolibarr
Products
dolibarr erp\/crm
Weakness
CWE-285, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.