Executive brief
Dolibarr ERP CRM, a popular open-source suite for managing business operations, contains a security flaw in its legacy file management component. This vulnerability allows an authenticated user to perform actions they are not authorized to do, potentially leading to unauthorized file access or modification. Organizations should upgrade to version 23.0.3 to ensure proper access controls are enforced.
Technical details
An improper authorization vulnerability exists in Dolibarr ERP CRM versions up to 23.0.2 within the Legacy Filemanager component. The flaw is located in the configuration file `htdocs/core/filemanagerdol/connectors/php/config.inc.php`, where a lack of sufficient permission checks allows authenticated users to interact with file management functions beyond their assigned privileges. An attacker with low-privileged network access can exploit this to perform unauthorized file operations. The issue was addressed in version 23.0.3 by implementing explicit permission tests for the file manager connector.
Affected products
- Dolibarr Dolibarr ERP CRM up to 23.0.2
Timeline
- 2026-06-09: advisory: NVD publication date
- 2023-05-17: patched: Release of version 23.0.3 containing the fix