CVE-2026-19930 | Dolibarr up to 23.0.3 User Cloning htdocs/user/card.php ID ldap injection (Issue 39000)
A vulnerability classified as critical was found in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection.
This vulnerability is known as CVE-2026-19930. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More