Executive brief
Dolibarr is an open-source enterprise resource planning (ERP) and customer relationship management (CRM) system used to manage business operations. A vulnerability in the email collector module allows an attacker to save files outside the intended attachment directory by sending emails with specially crafted filenames containing path traversal sequences. On systems where the web directory is writable, this enables placement of malicious files in web-executable directories for code execution; on hardened systems, it can corrupt other objects' files or forge document contents.
Technical details
The vulnerability is a path traversal flaw in Dolibarr's email attachment handling. The saveAttachment() functions in emailcollector.lib.php and emailcollector.class.php fail to sanitize attachment filenames before passing them to file_put_contents(), allowing directory traversal sequences (e.g., "../") in MIME header filenames to reach the filesystem. The attack requires no authentication or user interaction—any sender can exploit this by emailing a mailbox monitored by an EmailCollector instance. Exploitation can result in arbitrary file write to the documents tree or web-executable paths depending on file permissions. The flaw affects versions 9.0.0 through 23.0.4; version 24.0.0 applies dol_sanitizePathName() and dol_sanitizeFileName() functions to mitigate the issue.
Affected products
- Dolibarr Dolibarr 9.0.0 through 23.0.4
Timeline
- 2026-08-27: disclosed