Popis
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company-s WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim-s previous password verifier from the API response.
CVSS 7.1EPSS 0.233%Riziko 0.72
Zobraziť zdroj- Zverejnené
- 2026-08-24 19:16:49
- Dotknuté verzie
- <24.0.0
- Typ
- Webová aplikácia
- Posledná úprava
- 2026-08-24 20:17:11
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N