No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr
Dolibarr dolibarr Erp/crm |
|
| Vendors & Products |
Dolibarr
Dolibarr dolibarr Erp/crm |
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluation paths using PHP dynamic callable syntax to bypass validation and achieve arbitrary command execution via eval(). | |
| Title | Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() | |
| Weaknesses | CWE-95 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T13:43:14.034Z
Reserved: 2026-01-08T19:04:26.364Z
Link: CVE-2026-22666
No data.
Status : Awaiting Analysis
Published: 2026-04-07T13:16:45.200
Modified: 2026-04-07T13:20:11.643
Link: CVE-2026-22666
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:49:41Z