---
id: CVE-2025-67486
title: >-
  Dolibarr is an enterprise resource planning (ERP) and customer relationship
  management (CRM) software package
summary: >-
  Dolibarr is an enterprise resource planning (ERP) and customer relationship
  management (CRM) software package. Versions 22.0.2 and earlier contains an
  authenticated remote code execution vulnerability in the user extrafields
  functionalit…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-74
vendor: dolibarr
product: dolibarr_erp/crm
affected:
  - dolibarr_erp/crm <= 22.0.2
published: '2026-05-08'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T16:10:00.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67486'
references:
  - url: >-
      https://github.com/Dolibarr/dolibarr/blob/22.0.2/htdocs/core/lib/functions.lib.php
    label: security-advisories@github.com
  - url: >-
      https://medium.com/@abduxalilovjavohir/dolibarr-erp-authenticated-remote-code-execution-via-eval-injection-in-user-extrafields-dfc305d0118e
    label: security-advisories@github.com
  - url: >-
      https://medium.com/@abduxalilovjavohir/dolibarr-erp-authenticated-remote-code-execution-via-eval-injection-in-user-extrafields-dfc305d0118e
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00881
epssPercentile: 0.57747
ingestedAt: '2026-10-05T16:25:58.370Z'
---

## Overview

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is passed to PHP's `eval()` function without adequate sanitization, allowing authenticated administrators to execute arbitrary PHP code on the server. As of time of publication, no patched versions are available.

## Affected

- `dolibarr_erp/crm <= 22.0.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
