CVE-2026-19930
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 798e65356ede03c2812ab1a728f23fae34de5592. It is advisable to implement a patch to correct this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.24%
- CWE
- CWE-90, CWE-74
- Published
- 2026-08-16
- Last modified
- 2026-08-17
Affected products
- n/a Dolibarr
- n/a Dolibarr
- n/a Dolibarr
- n/a Dolibarr
Weakness type
Related vulnerabilities
- CVE-2026-80055 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78579 — Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
- CVE-2026-81205 — LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
- CVE-2026-75020 — Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
- CVE-2026-19271 — Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
- CVE-2026-76373 — Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
- CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication
- CVE-2026-16071 — Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary