PT-2026-45503 · Bottelet+1 · Daybyday Crm

·

CVE-2026-10282

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions Bottelet DaybydayCRM versions prior to 2.2.2
Description An improper authorization issue exists that can be exploited remotely. The flaw is located within the view() function of the app/Http/Controllers/DocumentsController.php file.
Recommendations Apply the security patch for versions prior to 2.2.2. As a temporary mitigation, restrict access to the view() function in the app/Http/Controllers/DocumentsController.php file.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10282

Affected Products

Daybyday Crm