PT-2022-15244 · Unknown · Daybyday Crm

Published

2022-01-05

·

Updated

2022-01-08

·

CVE-2022-22108

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Daybyday CRM versions 2.0.0 through 2.2.0
Description The issue allows an attacker with the lowest privileges account, specifically an employee type user, to view the absences of all users in the system, including administrators. This type of user is not authorized to view this kind of information.
Recommendations For Daybyday CRM versions 2.0.0 through 2.2.0, consider restricting access to absence viewing features to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the privileges of employee type users to prevent them from accessing sensitive information.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22108
GHSA-FRXP-XXX8-HRG6

Affected Products

Daybyday Crm