Cross Site Request Forgery Vulnerability in Dolibarr ERP & CRM
CVE-2025-69634

9CRITICAL

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
12 February 2026

What is CVE-2025-69634?

A Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows remote attackers to perform actions on behalf of users without their consent by exploiting the notes field in the perms.php file. This security flaw can lead to unauthorized privilege escalation, potentially compromising sensitive data and functionalities within the application.

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.