Impact
Dolibarr’s Online Signature module contains a flaw in the dol_verifyHash function that does not correctly verify cryptographic signatures. An attacker who can influence the verification process may craft or alter signatures so that the system accepts them as valid, enabling the submission of data or transactions that were not originally authenticated.
Affected Systems
Dolibarr ERP CRM, versions up to and including 23.0.2. The vulnerability exists in the Online Signature module’s security.lib.php component.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog. Exploitation can be performed remotely via the Online Signature interface; publicly released exploit code demonstrates practical leverage. The description notes that attacks are highly complex and exploitation difficulty is high, while the vendor’s failure to respond increases the exposure window.
OpenCVE Enrichment