CVE-2022-0731
23.02.2022, 19:15
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.Enginsight
Vendor | Product | Version |
---|---|---|
dolibarr | dolibarr_erp\/crm | 𝑥 < 16.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References