PT-2022-15244 · Unknown · Daybyday Crm
Published
2022-01-05
·
Updated
2022-01-08
·
CVE-2022-22108
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Daybyday CRM versions 2.0.0 through 2.2.0
Description
The issue allows an attacker with the lowest privileges account, specifically an employee type user, to view the absences of all users in the system, including administrators. This type of user is not authorized to view this kind of information.
Recommendations
For Daybyday CRM versions 2.0.0 through 2.2.0, consider restricting access to absence viewing features to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the privileges of employee type users to prevent them from accessing sensitive information.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daybyday Crm