CRITICAL9.8
GHSA-hxmh-2xc4-c894
Dolibarr ERP CRM contains a remote code evaluation vulnerability
Quick fix
GHSA-hxmh-2xc4-c894 — dolibarr/dolibarr: upgrade to the fixed version with the command below.
composer require dolibarr/dolibarr:^7.0.4Details
Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/dolibarr/dolibarr
Introduced in:
7.0.0Fixed in: 7.0.4Fix
composer require dolibarr/dolibarr:^7.0.4Packagist/dolibarr/dolibarr
Introduced in:
0Fixed in: 6.0.8Fix
composer require dolibarr/dolibarr:^6.0.8References
- https://nvd.nist.gov/vuln/detail/CVE-2018-25357[ADVISORY]
- https://github.com/Dolibarr/dolibarr/issues/9032[WEB]
- https://github.com/Dolibarr/dolibarr/commit/41709f07d0aef384723164877395ed081b44b810[WEB]
- https://dolibarr.org[WEB]
- https://github.com/Dolibarr/dolibarr[PACKAGE]
- https://www.exploit-db.com/exploits/44964[WEB]
- https://www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-via-install-step1-php[WEB]