In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.
References
| Link | Resource |
|---|---|
| https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31018/README.md | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-04-21 15:16
Updated : 2026-07-05 02:17
NVD link : CVE-2026-31018
Mitre link : CVE-2026-31018
CVE.ORG link : CVE-2026-31018
JSON object : View
Products Affected
dolibarr
- dolibarr_erp\/crm
