Executive brief
Dolibarr ERP CRM, an open-source suite used by businesses to manage customers and resources, contains a security flaw in its messaging component. An authenticated user can bypass normal authorization checks to view messages or data belonging to other users by manipulating identification numbers in web requests. This could lead to the unauthorized exposure of internal communications or sensitive user information.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Dolibarr ERP CRM versions 23.0.0 through 23.0.2 within the `htdocs/user/messaging.php` file. The application fails to properly validate if the requesting user has the necessary permissions to access a specific record identified by the 'ID' parameter. A remote, authenticated attacker can exploit this by manipulating the ID argument to bypass authorization checks and view data belonging to other users. The issue is rooted in an improper implementation of the `restrictedArea` check and has been addressed in version 23.0.3 by adding explicit ownership and permission validation.
Affected products
- Dolibarr Dolibarr ERP CRM 23.0.0, 23.0.1, 23.0.2
Timeline
- 2026-05-31: disclosed
- 2026-05-31: advisory
- 2023-05-17: patched: Date of GitHub release 23.0.3