The Back-Office Break-In: Nine Dolibarr Findings
Nine ways into the software that runs a small business and the one wall that was missing from all of them

Search for a command to run...
Series
A Series of our Security Research with Dolibarr
Nine ways into the software that runs a small business and the one wall that was missing from all of them

CVSS 9.3 · Reflected XSS (CWE-79), chained to admin creation · Fixed in Dolibarr 24.0.0 Think of a contractor's badge that, when scanned at reception, silently prints a second master key, and the guar
CVSS 8.3 · Mass assignment (CWE-915) · Fixed in Dolibarr 24.0.0 The front desk refuses to change the CEO's password. But the membership clerk's window, which nobody thought to lock will happily do it,
CVSS 8.1 · Broken object-level authorization (CWE-639) · Fixed in Dolibarr 24.0.0 The clerk who shows you a file first checks it's yours. The clerk who resets the password on that file never checks, s
CVSS 6.5 · Wrong-permission authorization (CWE-863) · Fixed in Dolibarr 24.0.0 The button labelled “delete a draft invoice” is wired to the vault that holds recorded payments. Press it and money that
CVSS 6.5 · Object-level auth bypass → SEPA payment redirection (CWE-639) · Fixed in Dolibarr 24.0.0 You can't see a supplier's account, but you can quietly edit the bank number the company will pay. W