Improper authorization control for web services In dolibarr/dolibarr
Description
Improper Authorization in dolibarr/dolibarr An Improper Authorization vulnerability exists in Dolibarr versions prior to version 15.0.0. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 15.0.0 |
Aliases
1. 2. 3. 4.
References
1. 2.