Description
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.3.x Cross-Site Scripting (3.3.0 - 3.3.3)
WebLogic Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2018-11040)
WordPress Plugin Content Copy Protection & Prevent Image Save Cross-Site Request Forgery (1.3)
WordPress Cryptographic Issues Vulnerability (CVE-2009-3622)