Impact
Dolibarr versions before 24.0.0 contain a flaw in the payments REST API delete endpoint where a permission check for payment creation is incorrectly performed. Authenticated users who possess invoice‑deletion rights can delete any payment record regardless of the intended payment‑issuance permissions. This allows an attacker to zero paid amounts on invoices and remove entries from accounting exports, thereby compromising the integrity of financial data.
Affected Systems
The vulnerability affects all Dolibarr installations running any release earlier than 24.0.0. Users should verify the exact version of Dolibarr deployed, as the security update was released in the 24.0.0 milestone.
Risk and Exploitability
The CVSS score for this issue is 7.2, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and hold invoice‑deletion privileges; no remote exploitation requirement is stated. Once these conditions are met, the attacker can permanently eliminate payment records and corrupt financial export data.
OpenCVE Enrichment