An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job type
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 27 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Execution in Dolibarr ERP/CRM Through Unvalidated Dynamic Function Calls | |
| Weaknesses | CWE-94 |
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job type | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T14:01:12.874Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37712
No data.
Status : Deferred
Published: 2026-05-27T15:16:26.887
Modified: 2026-05-27T20:03:09.937
Link: CVE-2026-37712
No data.
OpenCVE Enrichment
Updated: 2026-05-27T21:00:14Z
Weaknesses