Dolibarr ERP/CRM 版本低于 24.0.2 在文件 中存在不正确的授权漏洞。该文件在写入额外字段(extrafield)值时,仅检查了读取权限。具有只读权限的已认证用户可通过 POST 方法提交 、 、 和 参数,持久化地修改可查看的第三方客户、产品、成员、项目或联系人记录的额外字段数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet