Impact
Dolibarr versions earlier than 24.0.0 contain a broken object-level authorization flaw in the REST API third‑party write routes. The vulnerability allows an attacker who is authenticated and holds third‑party creation rights to overwrite the WebPortal password of any company, bypassing the per‑object access checks that are only applied on read operations. By replacing the victim’s WebPortal password, the attacker can log in as that company and retrieve sensitive invoice data, and can also obtain the previous password verifier from the API response, which could be used for further credential compromise.
Affected Systems
The flaw impacts Dolibarr deployments running any version older than 24.0.0, regardless of installation size or configuration, because the affected API route is part of the core REST service.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the vulnerability. The EPSS score is not available, but the fact that the exploitation requires only an authenticated user with existing third‑party creation rights makes the attack path relatively straightforward for internal or compromised accounts. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can effectively bypass authentication controls to take over a company’s WebPortal account, which could lead to broad access to financial records and other internal data. The risk to organizations is moderate to high, especially in environments where third‑party creation privileges are granted broadly.
OpenCVE Enrichment