Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts. | |
| Title | Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php | |
| First Time appeared |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T20:14:30.910Z
Reserved: 2026-10-08T16:52:24.550Z
Link: CVE-2026-107706
No data.
Status : Deferred
Published: 2026-10-08T20:17:35.503
Modified: 2026-10-08T20:17:35.640
Link: CVE-2026-107706
No data.
OpenCVE Enrichment
No data.
Weaknesses