PT-2024-22921 · Dolibarr · Dolibarr

Joao A. C. Buschinelli

·

Published

2024-04-03

·

Updated

2025-04-03

·

CVE-2024-29477

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP CRM versions up to 19.0.0
Description The issue is related to a lack of sanitization during the installation process, allowing an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input. This can lead to a critical privilege escalation. The attacker must have access to the local network to exploit this issue.
Recommendations For versions up to 19.0.0, update Dolibarr to a version that includes the fix for this issue. As a temporary workaround, consider limiting local network access to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2024-29477
CVE-2024-29477
GHSA-P73X-RPGM-3V56

Affected Products

Dolibarr