Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3991


An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.


Published

2024-11-15T11:15:07.173

Last Modified

2024-11-19T15:31:47.833

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-285
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dolibarr dolibarr_erp\/crm < 20.0.2 Yes

References