Dolibarr

Dolibarr

34 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Published 01.10.2025 20:18:36
  • Last modified 02.10.2025 19:11:46

Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.

  • EPSS 1.08%
  • Published 03.06.2024 20:15:09
  • Last modified 21.11.2024 09:17:59

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

Exploit
  • EPSS 0.27%
  • Published 15.12.2021 07:15:07
  • Last modified 21.11.2024 06:27:25

A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.

  • EPSS 0.33%
  • Published 17.08.2021 15:15:08
  • Last modified 21.11.2024 05:55:40

In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through ...

  • EPSS 0.37%
  • Published 17.08.2021 15:15:07
  • Last modified 21.11.2024 05:55:40

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account t...

  • EPSS 0.42%
  • Published 15.08.2021 21:15:06
  • Last modified 21.11.2024 05:55:40

In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. The...

  • EPSS 0.25%
  • Published 09.08.2021 17:15:07
  • Last modified 21.11.2024 05:55:40

In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field...

Exploit
  • EPSS 9.69%
  • Published 02.09.2020 17:15:11
  • Last modified 21.11.2024 05:02:52

Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control ...

Exploit
  • EPSS 0.15%
  • Published 21.08.2020 19:15:12
  • Last modified 21.11.2024 05:02:51

Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

  • EPSS 0.3%
  • Published 18.06.2020 18:15:11
  • Last modified 21.11.2024 05:03:17

A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.