Skip to content
Threat Feed

Vendor

Dolibarr

4 briefs RSS
high advisory

Authorization Bypass in Dolibarr Document Storage

An unauthenticated authorization bypass vulnerability in Dolibarr allows remote attackers to access arbitrary sensitive files via the document storage endpoints.

PoC Dolibarr web-vulnerability authorization-bypass
1r 1t 1c updated
high advisory

Dolibarr Members REST API Improper Authorization Vulnerability

An improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.

Dolibarr +2 vulnerability rest-api privilege-escalation cve-2026-71504 sqli web-vulnerability cve-2026-81730 path-traversal +1
2r 2t 1c updated
high threat

Dolibarr ERP/CRM OS Command Injection (CVE-2023-30253) Exploit Publicly Available

A public exploit is available for an OS Command Injection vulnerability in Dolibarr ERP/CRM versions prior to 17.0.1 (CVE-2023-30253), which allows authenticated users to inject PHP code via the Website/CMS module to obtain a reverse shell as the www-data user.

Dolibarr ERP/CRM < 17.0.1 cve-2023-30253 os command injection rce web application
2r 1t 1c 2i
critical advisory

Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php

Dolibarr ERP CRM 7.0.3 is vulnerable to remote code evaluation, allowing unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter, leading to arbitrary command execution.

Dolibarr ERP CRM 7.0.3 cve-2018-25357 rce code-injection web-application
2r 2t 1c