Remote Code Execution Vulnerability in Dolibarr ERP CRM Software
CVE-2024-40137

5.5MEDIUM

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
24 July 2024

What is CVE-2024-40137?

A remote code execution vulnerability exists in Dolibarr ERP CRM before version 19.0.2-php8.2, specifically through the Computed field parameter within the Users Module Setup function. This flaw may allow an authenticated attacker to execute arbitrary code on the server, potentially compromising sensitive data and the overall integrity of the application. Organizations using affected versions are encouraged to apply the necessary security updates to mitigate this risk.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.