CVE-2026-81728: Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and quotes intact. importinsert() in htdocs/core/modules/import/importcsv.modules.php then iterates the submitted values and builds a filter with $where[] = $key.' = '.$data[$key], having first applied pregreplace('/^.\./i', '', $key), an alias strip that does nothing to a value containing no dot. The assembled string is executed through $this->db->query(). The injected SELECT resolves the row id that the import then assigns to $lastinsertid, which becomes the WHERE target of a subsequent UPDATE, so a UNION SELECT returning an attacker-chosen integer both exfiltrates arbitrary table content and redirects which row the import overwrites; for category link tables the raw filter array is spliced into that UPDATE directly. The interface offers a fixed list of legitimate column codes but the server never checks the submitted values against it. A user holding the import permission can exploit this. Release 23.0.4 does not carry the fix; the allow-list test was added in 24.0.0.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs network access and low-level authenticated privileges, specifically access to the import functionality. No separate user interaction is required.
Does the import wizard's fixed list of column codes prevent malicious update keys?
No. Although the interface presents a fixed list of legitimate column codes, the server does not validate submitted update-key values against that list.