Impact
Dolibarr 24.0.0 contains a case‑sensitive denylist bypass in the sqlfilters API query parameter. An authenticated attacker can supply uppercase variants of denylist‑protected field names, causing the denylist check to fail while the database resolver remains case‑insensitive. This allows the attacker to recover protected database fields, including full password hashes for any user, even administrators.
Affected Systems
All Dolibarr instances running version 24.0.0 or earlier, not including 24.0.1 and later releases, are vulnerable to this bypass. The feature is triggered through the exposed sqlfilters API, so only systems with the API enabled are impacted.
Risk and Exploitability
The reported CVSS score of 7.1 reflects a high severity that compromises confidentiality. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploits yet. Exploitation requires valid authentication to the server; the attacker would craft an API request containing an uppercase protectively lookup field, rely on the mismatch between the case‑insensitive database resolution and the case‑sensitive denylist, and obtain password hashes. The presence of a generic authenticated API means that users with any valid credentials can attempt the attack without additional permissions.
OpenCVE Enrichment