CVE-2025-56588: n/a
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
AI Analysis
Technical Summary
CVE-2025-56588 is a remote code execution (RCE) vulnerability affecting Dolibarr ERP & CRM version 21.0.1. The issue exists in the User module configuration through the computed field parameter, which can be manipulated to execute arbitrary code remotely. The vulnerability is classified under CWE-94, indicating improper control over code generation. The CVSS score of 8.8 reflects a high-severity flaw exploitable over the network without privileges but requiring user interaction. No known exploits in the wild have been reported, and no patch or remediation details are currently available.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system remotely. This could lead to full compromise of the Dolibarr ERP & CRM instance, including unauthorized access to sensitive data, modification or deletion of data, and disruption of service. The high CVSS score reflects the critical impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. In the meantime, limit exposure by restricting access to the User module configuration interface and applying standard network protections. Avoid enabling or using computed fields in the User module until a fix is available.
CVE-2025-56588: n/a
Description
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
CVSS v3.1
Score 8.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-56588 is a remote code execution (RCE) vulnerability affecting Dolibarr ERP & CRM version 21.0.1. The issue exists in the User module configuration through the computed field parameter, which can be manipulated to execute arbitrary code remotely. The vulnerability is classified under CWE-94, indicating improper control over code generation. The CVSS score of 8.8 reflects a high-severity flaw exploitable over the network without privileges but requiring user interaction. No known exploits in the wild have been reported, and no patch or remediation details are currently available.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system remotely. This could lead to full compromise of the Dolibarr ERP & CRM instance, including unauthorized access to sensitive data, modification or deletion of data, and disruption of service. The high CVSS score reflects the critical impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. In the meantime, limit exposure by restricting access to the User module configuration interface and applying standard network protections. Avoid enabling or using computed fields in the User module until a fix is available.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-08-17T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
Threat ID: 68dd86de2801a4fa284df5db
Added to database: 10/01/2025, 19:54:06 UTC
Last enriched: 07/05/2026, 21:29:40 UTC
Last updated: 08/18/2026, 10:54:20 UTC
Views: 424
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.