Looking for the vulnerability index of Invicti's legacy products?
Dolibarr Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3991) - Vulnerability Database

Dolibarr Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-3991)

Description

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

References