Dolibarr < 24.0.0 - Authorization Bypass via hashp Parameter
Dolibarr ERP/CRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.