DEV Community

yutianle
yutianle

Posted on

Dolibarr: 4,209 title matches against 829 fingerprint matches on the same ERP

Dolibarr: 4,209 title matches against 829 fingerprint matches on the same ERP

Dolibarr is an open-source ERP and CRM package used by small and medium businesses, and it runs as a PHP application on a web server the business controls. That deployment model puts invoicing, customer records and stock data behind a login page that is sometimes reachable from the open internet. Measuring that population is a useful exercise in itself, because two ZoomEye fields return counts that differ by a factor of five for the same product.

The two measurements

Two queries executed on 2026-10-05 with the scope set to all asset types produced these counts.
| Query | Field | Count |
| --- | --- | ---: |
| app="Dolibarr" | Application fingerprint | 829 |
| title="Dolibarr" | HTML title | 4,209 |
The fingerprint field identifies the product from how the service behaves, which for a PHP application means the structures ZoomEye recognises in the response. The title field matches the text between the title tags of the returned page. Dolibarr ships a login page whose title contains the product name, so both queries find running installations, and they disagree about how many.

Why the two fields disagree

Three effects explain most of the gap. The fingerprint rule is narrower than a plain string match, so an installation whose pages do not present the expected structure is invisible to it. The title rule is broader, so pages that carry the product name in a title are matched even when the underlying behaviour does not resemble the pattern the fingerprint expects. Customised deployments, which are common for an ERP, change the login page and therefore change both signals in different directions.
Neither count is a count of vulnerable systems. ZoomEye records what it observed about an internet-facing asset, not which software version that asset runs, and no version information appears in either query result. The honest reading is that roughly four thousand assets present Dolibarr in a page title and several hundred match the fingerprint, and both numbers describe exposure rather than risk.

Why an exposed ERP deserves attention

The data behind the login page is the reason. An ERP holds customer lists, invoices, supplier bank details and pricing, and the accounts in it map to roles inside the business. The older Dolibarr vulnerability record shows how much authority the application carries: CVE-2018-13447 through CVE-2018-13450 describe SQL injection in product/card.php in version 7.0.3 through parameters such as statut, country_id and statut_buy, all scored 9.8. CVE-2018-10092 describes remote command execution in the admin panel of versions before 7.0.2 through the antivirus command configuration.
Those records are old, and current versions are not affected by them. They are still the clearest available statement of what the application can be made to do when an attacker reaches it, which is the same property that makes public exposure worth measuring.

What to do with the number

Treat the count as a reason to check your own inventory rather than a description of someone else's. Four practical steps follow from it.
Keep the application on the internal network or behind a VPN. An ERP is used by staff, not by the public, and the traffic pattern supports a strong network control.
Put authentication in front of the login page as well as inside it. Reverse-proxy authentication or a client certificate removes the unauthenticated case before the application code is reached.
Check the version and apply current updates. The historical records above are old, but the deployment habit that leaves an ERP on an old release is not.
Review file permissions and directory listings on the host. A PHP application that writes documents into a web-served directory can leak them independently of the application's own authentication.

Reproducing the queries

Both queries are reproducible in ZoomEye with the syntax below, and the counts above were recorded at the time of the search rather than taken from documentation.

  • app="Dolibarr" at 2026-10-05, scope all asset types
  • title="Dolibarr" at 2026-10-05, scope all asset types

References

  • ZoomEye query app="Dolibarr", sub_type=all, executed 2026-10-05
  • ZoomEye query title="Dolibarr", sub_type=all, executed 2026-10-05
  • NVD records for CVE-2018-13447, CVE-2018-13448, CVE-2018-13449 and CVE-2018-13450, retrieved 2026-10-05
  • NVD record for CVE-2018-10092, retrieved 2026-10-05
  • Dolibarr project documentation, retrieved 2026-10-05

Top comments (0)