Impact
This flaw resides in the TakePOS Module’s invoice.php file and removes the required authorization step in the function fail. Attackers can invoke the vulnerable code remotely, creating or manipulating invoices without proper clearance.
Affected Systems
Dolibarr ERP users running any version up to and including 23.0.3 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. It is not listed in CISA KEV. The attack vector is inferred to be remote, as the vulnerability can be exercised over the network by accessing the invoice endpoint. Without remediation, an attacker could create or alter invoices and gain financial privileges.
OpenCVE Enrichment