GHSA-w6rp-4vj7-v2m8
Dashboard / Vulnerabilities / GHSA-w6rp-4vj7-v2m8
Summary: Missing Authorization in DayByDay CRM
Details: In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-22111, https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b, https://github.com/Bottelet/DaybydayCRM, https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111
Affected packages
Package
Name: bottelet/flarepoint
Purl: pkg:composer/bottelet/flarepoint
Affected ranges
Type: ECOSYSTEM
Events:
