Impact
In Dolibarr versions prior to 24.0.0, the expense report REST API update endpoint permits an authenticated user with basic expense‑creation permissions to change the approval status and approver identity fields directly. This flaw allows the user to bypass the standard approval workflow and advance expense reports to approved or closed states without possessing the dedicated approval rights, thereby compromising the integrity of the financial approval process and creating forensic inconsistencies in audit records.
Affected Systems
Dolibarr installations running any version earlier than 24.0.0 are affected. The vulnerability affects the expense report REST API update endpoint, which is accessible to authenticated users who have the expense‑creation permission.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity issue. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and have the expense‑creation right; they can then craft API requests to modify workflow state fields, exploiting the improper authorization weakness (CWE‑862). The attack vector is limited to legitimate API use, but any user with the stated permissions can exploit the flaw without additional privileges.
OpenCVE Enrichment