Aller au contenu

Fiche vulnérabilité

CVE-2021-3991 : faille moyenne dolibarr dolibarr erp\/crm (CVSS 4.3)

Description

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

En bref

Sévérité
Moyenne (CVSS 4.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
15 nov. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • dolibarr dolibarr erp\/crm

Références

Rechercher une autre vulnérabilité dans la base CVE