Description
A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to improper authorization. The attack may be launched remotely. It is best practice to apply a patch to resolve this issue.
Problem types
Incorrect Privilege Assignment
Product status
2.2.1
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
Mitchell45 (VulDB User)
References
vuldb.com/vuln/367575 (VDB-367575 | Bottelet DaybydayCRM DocumentsController.php view improper authorization)
vuldb.com/vuln/367575/cti (VDB-367575 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10282 (CVE-2026-10282 | CVE Analysis and Report)
vuldb.com/submit/825439 (Submit #825439 | Bottelet DaybydayCRM <= 2.2.1 Insecure Direct Object Reference (IDOR) / Improper Authorization)
vuldb.com/submit/825440 (Submit #825440 | Bottelet DaybydayCRM <= 2.2.1 Improper Authorization (Duplicate))
github.com/Bottelet/DaybydayCRM/issues/347
github.com/Bottelet/DaybydayCRM/pull/362
github.com/Bottelet/DaybydayCRM/