CVE-2021-25954: Incorrect Authorization
(updated )
Dolibarr applications do not restrict, or incorrectly restricts, access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note
which only an administrator should have rights to do, the affected field is in the /adherents/note.php?id=1
endpoint.
References
Detect and mitigate CVE-2021-25954 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →