← Voltar à pesquisa de CVEs

CVE-2026-71505

Dolibarr

Descrição

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company-s WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim-s previous password verifier from the API response.

CVSS 7.1EPSS 0.233%Risco 0.72
Ver fonte
Publicação
2026-08-24 19:16:49
Versões afetadas
<24.0.0
Tipo
Aplicação web
Última alteração
2026-08-24 20:17:11
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N