CyberRota Analysis
AI-GeneratedDolibarr versions prior to 24.0.0 are vulnerable due to an improper authorization flaw in the user REST API update endpoint, allowing users with write permissions to manipulate payroll fields. This exploitation enables unauthorized modifications of sensitive payroll information, such as salaries and bonuses, which can subsequently appear in payroll export reports. Organizations using Dolibarr should prioritize addressing this vulnerability to prevent potential financial discrepancies and unauthorized access to payroll data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.