Vulnerability Description
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | <= 7.0.3 |
Related Weaknesses (CWE)
References
- https://dolibarr.orgProduct
- https://github.com/Dolibarr/dolibarrProduct
- https://www.exploit-db.com/exploits/44964ExploitVDB Entry
- https://www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-viaThird Party Advisory
FAQ
What is CVE-2018-25357?
CVE-2018-25357 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can...
How severe is CVE-2018-25357?
CVE-2018-25357 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-25357?
Check the references section above for vendor advisories and patch information. Affected products include: Dolibarr Dolibarr Erp\/Crm.