CVE-2025-69634Disclosure

LOWCVSS 9.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token of an admin user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-352CWE-598

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-12: 3Technical Details · 2026-02-12: 302-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69634 Cross-Site Request Forgery in Dolibarr ERP & CRM v.22.0.9 Enables Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69634

    Post summary

    A CSRF vulnerability (CVE‑2025‑69634) in Dolibarr 22.0.9 enables privilege escalation; no PoC, exploit, or patch information is provided.

    0001052
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-69634: CRITICAL] Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php#cve,CVE-2025-69634,#cybersecurity https://cvefind.com/CVE-2025-69634

    Post summary

    The tweet announces a critical CSRF flaw in Dolibarr ERP & CRM v.22.0.9 that permits privilege escalation through the notes field in perms.php.

    0000049
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-69634 - Critical Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php https://www.thehackerwire.com/vulnerability/CVE-2025-69634/ https://t.co/lMhA9okfe6

    Post summary

    The post reports a critical CSRF flaw in Dolibarr v.22.0.9 that can lead to privilege escalation; no PoC, exploit, patch, or active exploitation details are included.

    0000071
    112 followersView on X

Explore more