GHSA-frxp-xxx8-hrg6

Suggest an improvement
Source
https://github.com/advisories/GHSA-frxp-xxx8-hrg6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-frxp-xxx8-hrg6/GHSA-frxp-xxx8-hrg6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-frxp-xxx8-hrg6
Aliases
Published
2022-01-08T00:31:52Z
Modified
2024-02-19T05:26:35.147310Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Missing Authorization in DayByDay CRM
Details

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

Database specific
{
    "nvd_published_at": "2022-01-05T15:15:00Z",
    "cwe_ids": [
        "CWE-862"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-01-07T20:43:46Z"
}
References

Affected packages

Packagist / bottelet/flarepoint

Package

Name
bottelet/flarepoint
Purl
pkg:composer/bottelet/flarepoint

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.2.1

Affected versions

2.*

2.0.0
2.1.0
2.2.0