Impact
An unauthenticated attacker can supply a specially crafted hashp parameter value in the document.php and viewimage.php endpoints to bypass token verification while still meeting authorization checks. This allows the attacker to download arbitrary files from the document storage, including application logs, business documents, database backups that may contain password hashes, and files belonging to other multicompany entities. The weakness is an Authorization Bypass (CWE‑863). It is inferred from the description that the vulnerability can be triggered by a simple unauthenticated HTTP request.
Affected Systems
The vulnerability affects Dolibarr installations running any 23.x release from 23.0.4 up to but not including 24.0.1. Deployments that expose the document.php or viewimage.php endpoints over the web without additional protection are susceptible, regardless of the multicompany configuration.
Risk and Exploitability
The flaw has a CVSS score of 8.7, indicating high impact. The EPSS score of 2% suggests a low but non‑zero probability of exploitation; nevertheless, because the vulnerability can be triggered with a simple unauthenticated HTTP request containing a crafted hashp parameter, it remains a significant risk to deployments exposing document.php or viewimage.php. Although it is not listed in the CISA KEV catalog, its high CVSS score and the lack of authentication requirements make it a priority for close monitoring and immediate remediation.
OpenCVE Enrichment