Junglewise Threat Intelligence

CVE-2025-56588: Dolibarr ERP & CRM remote code execution in User module computed field

CVE-2025-56588 · Severity: high · CVSS 8.8 · Published 2025-10-01

Technologies: Dolibarr Erp\, Dolibarr Crm, Dolibarr ERP/CRM. Vendors: Dolibarr.

Executive brief

Dolibarr ERP & CRM, a popular open-source suite for managing business operations and customer relationships, contains a security flaw in its User module. An attacker with administrative access can exploit the 'computed field' feature to run unauthorized commands on the underlying server. This could lead to a complete takeover of the application, theft of sensitive business data, or disruption of operations.

Technical details

A remote code execution (RCE) vulnerability exists in Dolibarr ERP & CRM v21.0.1 within the User module's extra fields configuration. The flaw is classified as a code injection (CWE-94) where administrator-defined expressions in 'computed fields' are improperly sanitized before evaluation during page rendering. This vulnerability specifically bypasses previous mitigations implemented for CVE-2024-40137. While the CVSS vector suggests a requirement for user interaction, the primary attack vector involves an authenticated administrator modifying field parameters to achieve server-side execution. A patch has been committed to the Dolibarr GitHub repository to address this issue.

Affected products

  • Dolibarr Dolibarr ERP & CRM 21.0.1

Timeline

  • 2025-07-12: disclosed: Reported to vendor and MITRE
  • 2025-09-29: patched: Patch committed to GitHub repository
  • 2025-10-01: advisory: CVE published by NVD

References

Related threats