CVE-2021-3991

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
15/11/2024
Last modified:
19/11/2024

Description

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* 20.0.2 (excluding)