Impact
A flaw in Dolibarr’s user cloning component allows manipulation of the ID parameter in card.php to inject arbitrary LDAP query fragments. This improper handling of special characters enables an attacker to perform unauthorized LDAP queries, potentially reading or modifying directory data. The vulnerability may also be exploited to bypass authentication mechanisms or exfiltrate sensitive information stored in an LDAP server.
Affected Systems
Any deployment of Dolibarr up to version 23.0.3 is affected. The weakness resides in the card.php file within the user cloning feature and applies to all builds that have not incorporated the patch identified by commit 798e65356ede03c2812ab1a728f23fae34de5592.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the public release of the exploit and the lack of mitigation measures elevate real‐world risk. The EPSS score is not available; however, the fact that an exploit is already in circulation means an attacker can potentially launch remote attacks without having to discover the flaw. The vulnerability is not listed in CISA’s KEV catalog, yet the remote nature and LDAP impact warrant prompt attention.
OpenCVE Enrichment