CVE-2026-31018: Code Injection
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31018?
CVE-2026-31018 is classified as a medium severity vulnerability due to improper input validation allowing PHP code injection.
How do I fix CVE-2026-31018?
To fix CVE-2026-31018, upgrade Dolibarr ERP & CRM to version 22.0.5 or later, which addresses the oversight in input parameter handling.
Who is affected by CVE-2026-31018?
CVE-2026-31018 affects users of Dolibarr ERP & CRM versions up to and including 22.0.4.
What type of vulnerability is CVE-2026-31018?
CVE-2026-31018 is a code injection vulnerability that allows an authenticated user to inject malicious PHP code.
What are the potential impacts of CVE-2026-31018?
Potential impacts of CVE-2026-31018 include unauthorized execution of PHP code on the server, which may lead to data breaches or system compromise.