PT-2026-81001 · Dolibarr · Dolibarr
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dolibarr versions prior to 24.0.0
Description
An improper authorization issue exists in the payments REST API delete endpoint. Authenticated attackers with invoice-deletion rights can bypass the required payment-issuance rights check to permanently delete any payment record. This flaw allows attackers to zero out paid amounts on invoices and remove entries from accounting exports, leading to a loss of financial data integrity.
Recommendations
Update to version 24.0.0 or later.
Restrict API access to minimize the risk of exploitation.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolibarr