GHSA-wmrw-8344-fj44MediumCVSS 4.3

Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.

🔗 References (6)