Executive brief
Dolibarr is an open-source ERP/CRM application used by businesses to manage operations like invoicing, inventory, and accounting. A weakness in the Legacy File Manager component allows authenticated users without proper permissions to upload files and browse the media directory, potentially exposing or modifying sensitive business documents.
Technical details
The vulnerability is an improper access control flaw in the Legacy File Manager connector (htdocs/core/filemanagerdol/connectors/php/config.inc.php). The component failed to properly validate website write permissions before allowing file upload and media directory browsing. Any authenticated user could reach the connector and perform file operations regardless of their assigned permissions. The issue affects versions up to 21.0.4, 22.0.5, and 23.0.3. A fix was implemented in commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec by enforcing proper permission checks. Upgrading to version 23.0.4 or later resolves the issue.
Affected products
- Dolibarr Dolibarr up to 21.0.4, 22.0.5, and 23.0.3
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: Fix available in version 23.0.4 and commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec