CVE-2026-34036 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local Fi…
Medium CVSS: 6.5

CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.
Vendor
Dolibarr
Product
Dolibarr Erp\/crm
CWE
CWE-98
Yayın Tarihi
2026-03-31 03:15:57
Güncelleme
2026-04-03 16:54:36
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar