Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-25954

In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.2%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2021-25954


Contact Us

Shodan ® - All rights reserved