CVE-2025-56588
8.8Dolibarr · ERP & CRM
Dolibarr ERP & CRM version 21.0.1 contains a remote code execution vulnerability in the User module configuration, specifically triggered via the computed field parameter.
Executive summary
Dolibarr ERP & CRM version 21.0.1 is vulnerable to remote code execution, which could allow an attacker to gain full control over the affected system.
Vulnerability
This vulnerability is a remote code execution flaw located within the User module configuration. The issue is triggered by an attacker manipulating the computed field parameter, which allows for the execution of arbitrary code on the underlying server.
Business impact
The ability for an unauthenticated or remote attacker to execute arbitrary code poses a catastrophic risk to the organization. Successful exploitation could lead to total system compromise, unauthorized access to sensitive financial and operational data, and complete operational downtime. With a CVSS score of 8.8, this vulnerability is classified as High and requires immediate attention to prevent malicious activity.
Remediation
Immediate Action: Update your Dolibarr ERP & CRM installation to version 21.0.3 or later to apply the necessary security patches.
Proactive Monitoring: Monitor server access logs and application logs for unusual patterns, specifically focusing on requests directed toward the User module configuration or suspicious input in parameters.
Compensating Controls: Deploy a Web Application Firewall with rules configured to inspect and block malicious payloads targeting ERP application parameters until the update can be applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for full system compromise via remote code execution, this vulnerability represents a significant threat to your infrastructure. Security teams should prioritize the update to version 21.0.3 immediately. Failure to patch may expose the organization to unauthorized access and severe data loss.