PT-2026-36693 · Unknown · Dolibarr Erp/Crm
Yan1451
·
Published
2026-05-03
·
Updated
2026-05-03
·
CVE-2026-7689
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dolibarr ERP CRM versions prior to 23.0.3
Description
A flaw in the Online Signature Module allows for improper verification of cryptographic signatures. This issue occurs within the
dol verifyHash() function located in the htdocs/core/lib/security.lib.php library. A remote attacker can exploit this weakness, although the attack is considered highly complex and difficult to execute.Recommendations
Update to a version later than 23.0.2.
As a temporary workaround, restrict access to the
dol verifyHash() function in the htdocs/core/lib/security.lib.php library to minimize the risk of exploitation.Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dolibarr Erp/Crm