CVE-2021-3991

MEDIUM

Dolibarr Erp/crm < 20.0.2 - Improper Authorization

Title source: rule
STIX 2.1

Description

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-285
Status published
Products (2)
dolibarr/dolibarr 0 - 15.0.0Packagist
dolibarr/dolibarr_erp\/crm < 20.0.2
Published Nov 15, 2024
Tracked Since Feb 18, 2026