Impact
The vulnerability resides in Dolibarr’s Legacy File Manager component, specifically the configuration file located at htdocs/core/filemanagerdol/connectors/php/config.inc.php. Manipulation of this file can lead to improper access controls, allowing attackers to bypass intended restrictions. The flaw may be exploited remotely, and publicly available exploits have been released, indicating that the vulnerability could be used for attacks.
Affected Systems
Affected systems include Dolibarr installations running any of the following versions: 21.0.4, 22.0.5, and 23.0.3. Upgrading to version 23.0.4 or later incorporates a patch (commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec) that resolves the issue.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. EPSS is not available, but the existence of public exploits suggests that the vulnerability could be used in practice. The flaw can be triggered remotely and is not listed in the CISA KEV catalogue. Attackers may exploit the improper access controls to read or modify files that should be protected, potentially compromising confidentiality and integrity.
OpenCVE Enrichment