Impact
Dolibarr applications before version 23.0.4 permit document removal through a REST API endpoint that performs a read‑permission check instead of the required write check. An authenticated API user that holds only read privileges on a module that stores documents can therefore delete those documents permanently. This loss removes third‑party files, invoices, orders, proposals, project files and generated PDFs with no recovery mechanism, directly affecting the integrity and availability of business data.
Affected Systems
This flaw is present in Dolibarr ERP/CRM releases up to and including 23.0.3 and is fixed in version 23.0.4. All instances of Dolibarr that expose the REST API for document handling with a read‑only user role are susceptible.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity vulnerability. No EPSS data is provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation may not yet be widespread but is still credible. Because the attack requires only an authenticated user with read privileges, privilege escalation is difficult but not impossible, and the REST endpoint is typically external to the web UI, the nominal attack surface is moderate. The impact is significant due to the irreversible nature of the deletion.
OpenCVE Enrichment