Description
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
Remediation
References
Related Vulnerabilities
Atlassian Jira CVE-2019-8442 Vulnerability (CVE-2019-8442)
Atlassian Jira CVE-2019-11583 Vulnerability (CVE-2019-11583)
WordPress Plugin Duplicate Page Multiple Vulnerabilities (2.3)
WordPress Plugin RB Agency Local File Disclosure (2.4.7)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5651)