Command Injection in dolibarr - CVE-2018-10092

 

Command Injection in dolibarr - CVE-2018-10092

Published: May 22, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31295
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10092
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.


Affected software

dolibarr

How to mitigate CVE-2018-10092

Install update from vendor's website.

dolibarr - update to 7.0.2

External References

Related Security Bulletins