Impact
Dolibarr versions prior to 24.0.0 contain an improper authorization flaw in the user REST API update endpoint. Attackers who possess generic user‑write rights but not payroll permissions can target the payroll fields in the update payload. By sending update requests that include salary, bonus, hourly rate, daily rate, or weekly hours, an attacker can rewrite those values for any user. The altered information is reflected in payroll export reports, effectively enabling covert manipulation of financial compensation data and undermining confidentiality and integrity of payroll records.
Affected Systems
The vulnerability affects all Dolibarr installations running a version older than 24.0.0. It is tied to the Dolibarr core product and targets the REST API used for user updates.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. Although an EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the flaw requires only authenticated API access with user‑write privileges, a condition common in many business deployments. The lack of a public exploit does not reduce the likelihood that an attacker could craft a custom payload; the flaw is trivially exploitable through the documented API endpoint.
OpenCVE Enrichment