CVE-2021-3991

MEDIUM4.3EPSS 0.05%

Improper Authorization in dolibarr/dolibarr

Published: 11/15/2024Modified: 5/20/2025
Also known as:GHSA-wppr-j57c-8jpmBIT-dolibarr-2021-3991

Description

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

References (4)