CVE-2026-107706
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
08/10/2026
Last modified:
08/10/2026
Description
Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/Dolibarr/dolibarr
- https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80
- https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8
- https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php


