CRITICAL 9.8
GHSA-hxmh-2xc4-c894
Dolibarr ERP CRM contains a remote code evaluation vulnerability
Details
Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / dolibarr/dolibarr
Introduced in:
7.0.0 Fixed in: 7.0.4 Fix
composer require dolibarr/dolibarr:^7.0.4 Packagist / dolibarr/dolibarr
Introduced in:
0 Fixed in: 6.0.8 Fix
composer require dolibarr/dolibarr:^6.0.8 References
- https://nvd.nist.gov/vuln/detail/CVE-2018-25357 [ADVISORY]
- https://github.com/Dolibarr/dolibarr/issues/9032 [WEB]
- https://github.com/Dolibarr/dolibarr/commit/41709f07d0aef384723164877395ed081b44b810 [WEB]
- https://dolibarr.org [WEB]
- https://github.com/Dolibarr/dolibarr [PACKAGE]
- https://www.exploit-db.com/exploits/44964 [WEB]
- https://www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-via-install-step1-php [WEB]