CVE-2024-40137: Dolibarr Erp\/crm

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

Affected products

  • Dolibarr Dolibarr Erp\/crm: from 18.0.5-php8.1, before 19.0.2-php8.2 (fixed in 19.0.2-php8.2)

Published 2024-07-24. Last modified 2026-06-17.