CVE-2021-25954: Improper Access Control in “Dolibarr”
Published Aug 9, 2021
·Updated
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
Affected Software
1 affected component
dolibarr Dolibarr>=2.8.1<=13.0.4
Remediation
Information
Update to 14.0.0
Event History
Aug 9, 2021
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25954.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In “Dolibarr” application 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource.'
3
What is the affected software?
The affected software is Dolibarr version 2.8.1 to 13.0.4.
4
What is the severity of CVE-2021-25954?
The severity of CVE-2021-25954 is medium with a CVSS score of 4.3.
5
How can an attacker exploit this vulnerability?
A low privileged attacker can modify the Private Note field in the Dolibarr application, which should only be accessible to administrators.