Impact
The vulnerability allows an attacker to manipulate the ID parameter in Dolibarr's User Notes handler, resulting in an authorization bypass that grants unauthorized access to sensitive note data. This flaw is present in the processing of /user/note.php within the User Notes module. The impact is predominantly a loss of confidentiality and integrity, enabling unauthorized users to view or modify notes that should be restricted, potentially leading to privilege escalation within the application.
Affected Systems
Dolibarr ERP software is affected. Versions up to 18.0.10, 22.0.5, and 23.0.3 contain the flaw. The patch included in the 23.0.4 and 24.0.0 releases resolves the issue. The affected component is the User Notes handler located at /user/note.php.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The attacker can initiate the exploit remotely by modifying the ID argument, leading to an authorization bypass. No additional conditions are noted, so the attack is considered straightforward for threat actors who can reach the application or have compromised user credentials.
OpenCVE Enrichment