← Volver al buscador de CVEs

CVE-2026-71505

Dolibarr

Descripción

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company-s WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim-s previous password verifier from the API response.

CVSS 7.1EPSS 0.233%Riesgo 0.72
Ver fuente
Publicación
2026-08-24 19:16:49
Versiones afectadas
<24.0.0
Tipo
Aplicación web
Última modificación
2026-08-24 20:17:11
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N