{"id":"CVE-2021-25954","aliases":["GHSA-vxhc-c4qm-647p"],"url":"https://o3.security/vulnerability/CVE-2021-25954","summary":"Improper Access Control in Dolibarr","details":"In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at “/adherents/note.php?id=1” endpoint.","published":"2021-08-09T17:15:07.307Z","modified":"2026-08-07T15:15:15.754856Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"dolibarr/dolibarr","fixedVersion":"14.0.0"}],"fix":{"url":"https://github.com/Dolibarr/dolibarr/commit/8cc100012d46282799fb19f735a53b7101569377","label":"Dolibarr/dolibarr@8cc1000"},"references":[{"type":"ADVISORY","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25954"},{"type":"FIX","url":"https://github.com/Dolibarr/dolibarr/commit/8cc100012d46282799fb19f735a53b7101569377"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:15:15.754856Z"}}