4.3
CVSSv3

CVE-2022-22108

Published: 05/01/2022 Updated: 08/01/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In Daybyday CRM, versions 2.0.0 up to and including 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

daybydaycrm daybyday crm