PT-2026-79794 · Unknown · Dolibarr Erp
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dolibarr ERP versions prior to 18.0.11
Dolibarr ERP versions prior to 22.0.6
Dolibarr ERP versions prior to 23.0.4
Description
An authorization bypass exists in the User Notes Handler component due to improper processing of the
/user/note.php endpoint. A remote attacker can exploit this by manipulating the ID argument to bypass security checks.Recommendations
Update to version 23.0.4.
Update to version 24.0.0.
As a temporary mitigation, restrict access to the
/user/note.php file.Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dolibarr Erp