CVE-2021-3991: Improper Authorization in dolibarr/dolibarr
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
Other sources
An Improper Authorization vulnerability exists in Dolibarr versions prior to version 15.0.0. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3991?
CVE-2021-3991 has a medium severity rating due to improper authorization that can be exploited by a user with restricted permissions.
How do I fix CVE-2021-3991?
To fix CVE-2021-3991, upgrade Dolibarr to version 15.0.0 or later.
What versions are affected by CVE-2021-3991?
CVE-2021-3991 affects Dolibarr versions prior to the 'develop' branch and before version 15.0.0.
What impact does CVE-2021-3991 have on user data?
CVE-2021-3991 allows unauthorized users to access specific reception details, potentially exposing sensitive information.
Is there a patch available for CVE-2021-3991?
Yes, a patch is available in Dolibarr version 15.0.0 and later, addressing the improper authorization issue.