← Zurück zur CVE-Suche

CVE-2026-71505

Dolibarr

Beschreibung

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company-s WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim-s previous password verifier from the API response.

CVSS 7.1EPSS 0.233%Risiko 0.72
Quelle öffnen
Veröffentlicht
2026-08-24 19:16:49
Betroffene Versionen
<24.0.0
Typ
Webanwendung
Zuletzt geändert
2026-08-24 20:17:11
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N