GHSA-rvwr-q5hj-wq7g

Suggest an improvement
Source
https://github.com/advisories/GHSA-rvwr-q5hj-wq7g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rvwr-q5hj-wq7g/GHSA-rvwr-q5hj-wq7g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rvwr-q5hj-wq7g
Aliases
  • CVE-2026-7688
Published
2026-05-03T12:30:26Z
Modified
2026-05-11T16:37:31.721690Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Dolibarr has an Injection issue
Details

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-74"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-11T16:21:37Z",
    "nvd_published_at": "2026-05-03T10:16:17Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / dolibarr/dolibarr

Package

Name
dolibarr/dolibarr
Purl
pkg:composer/dolibarr/dolibarr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
23.0.2

Affected versions

3.*
3.6.0-beta
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0-beta
3.8.0
3.8.1
3.8.2
3.8.3
3.8.4
3.9.0-rc
3.9.0-rc2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
4.*
4.0.0-beta
4.0.0-rc
4.0.0-rc2
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
5.*
5.0.0-beta
5.0.0-rc1
5.0.0-rc2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
6.*
6.0.0-beta
6.0.0-rc
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
9.*
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
10.*
10.0.0
10.0.1
10.0.2
10.0.3
10.0.4
10.0.5
10.0.6
10.0.7
11.*
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
12.*
12.0.0
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
13.*
13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
14.*
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
15.*
15.0.0
15.0.1
15.0.2
15.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-rvwr-q5hj-wq7g/GHSA-rvwr-q5hj-wq7g.json"