fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-19350. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-19350 | Dolibarr ERP up to 23.0.3 TakePOS invoice.php fail authorization (Issue 38949 / EUVD-2026-54918)
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability was found in Dolibarr ERP up to 23.0.3 and classified as critical. Affected is the function
SOCIAL SHARE CARD GENERATOR