CVE-2025-67486 - CVE House
Back to Database
Status published High CVE-2025-67486

Dolibarr has an Authenticated Remote Code Execution via eval() injection in user extrafields

Vulnerability Description

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is passed to PHP's `eval()` function without adequate sanitization, allowing authenticated administrators to execute arbitrary PHP code on the server. As of time of publication, no patched versions are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67486

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dolibarr
Vulnerable Versions:
<= 22.0.2

Timeline

Official Publish: May 8th, 2026
Last Modified: May 8th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)