Missing Authorization in DayByDay CRM
Moderate severity
GitHub Reviewed
Published
to the GitHub Advisory Database
•
Updated
Description
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.
References
Published by the National Vulnerability Database
Reviewed
Published to the GitHub Advisory Database
Last updated
Severity
Moderate
/ 10
CVSS v3 base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS score
(48th percentile)
Weaknesses
CVE ID
CVE-2022-22108
GHSA ID
GHSA-frxp-xxx8-hrg6
Source code
See something to contribute?
Suggest improvements for this vulnerability.
