Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-34036

4 месяца назад

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-34036

4 месяца назад

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-34036

4 месяца назад

Dolibarr is an enterprise resource planning (ERP) and customer relatio ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mfj-r695-5h9r

4 месяца назад

Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

CVSS3: 6.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logs…). At time of publication, there are no publicly available patches.

CVSS3: 6.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relatio ...

CVSS3: 6.5
1%
Низкий
4 месяца назад
github логотип
GHSA-2mfj-r695-5h9r

Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php

CVSS3: 6.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу