[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":48,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":55,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":61,"vulnerability-29772":68},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":41,"text":42,"link":43,"external":44,"targets":45,"cta":47,"variant":13,"campaign_id":41},"Office Hours #12 - 5 offensive security topics that actually matter","office-hours-12","[Live Office Hours, Wed Sept 30] 5 offensive security topics that actually matter","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_aPuMw5m2TEyAcn9ZEbE8uQ",true,[46],"\u002F","Save your spot",["Island",49],{"key":50,"params":51,"result":53},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":52},"{}",{"head":54},{},["Island",56],{"key":57,"params":58,"result":59},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":52},{"head":60},{},["Island",62],{"key":63,"params":64,"result":66},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":65},"{\"text-color\":\"gray\"}",{"head":67},{},{"id":69,"detectable_with":70,"vuln_details":77,"vuln_id":99,"name":100,"published":101,"updated":78},29772,{"tool":71,"engine":74},{"id":72,"name":73},1,"Network Scanner",{"id":75,"name":76},2,"Nuclei",{"id":69,"codename":78,"description":78,"severity":79,"risk_description":80,"public_description":81,"public_recommendation":82,"recommendation":78,"references":83,"cvssv3":92,"epss_score":93,"epss_percentile":94,"cve":95,"in_cisa_catalog":9,"date":97,"software_type":78,"vendor":98,"product":98,"ptt_exploit_capabilities":78},null,"high","Unauthenticated remote attackers can read arbitrary files from all Dolibarr managed directories, potentially exposing database credentials, invoices, contracts, and other sensitive data.","Dolibarr ERP\u002FCRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.","Upgrade Dolibarr to version 24.0.1 or later.",[84,85,86,87,88,89,90,91],"https:\u002F\u002Fgithub.com\u002FFaceless0x7\u002FCVE-2026-89013","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Fcommit\u002Fcd05688dbed8a4af6eef32faf4fc1e823a37bce9","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Fcommit\u002Fa8bc4a63e1b6356884abcd83c4a38954d9649b0b","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Fcommit\u002F3bd8aa8b909e596d7dab4388d0466ec24e6ad191","https:\u002F\u002Fgithub.com\u002FDolibarr\u002Fdolibarr\u002Freleases\u002Ftag\u002F24.0.1","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fdolibarr-authorization-bypass-via-hashp-parameter-in-document-php","https:\u002F\u002Fprevidian.com\u002FCVE-2026-89013","http:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-89013",7.5,0.00496,0.40121,[96],"CVE-2026-89013","2026-09-11T00:00:00Z","dolibarr","NETSCAN-NUCLEI-CVE-CVE-2026-89013","Dolibarr \u003C 24.0.0 - Authorization Bypass via hashp Parameter","2026-09-28T00:00:00Z"]