PT-2026-45503 · Bottelet+1 · Daybyday Crm
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
Bottelet DaybydayCRM versions prior to 2.2.2
Description
An improper authorization issue exists that can be exploited remotely. The flaw is located within the
view() function of the app/Http/Controllers/DocumentsController.php file.Recommendations
Apply the security patch for versions prior to 2.2.2.
As a temporary mitigation, restrict access to the
view() function in the app/Http/Controllers/DocumentsController.php file.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Daybyday Crm