vendor:
Dolibarr ERP & CRM
by:
Nahuel Grisolia
8,5
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:C)
Injection
78
CWE
Product Name: Dolibarr ERP & CRM
Affected Version From: Dolibarr <= 3.1.1
Affected Version To: Dolibarr <= 3.2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:dolibarr:dolibarr_erp_crm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web Server
2012
Dolibarr ERP & CRM OS Command Injection
Dolibarr is prone to remote command execution vulnerability because the software fails to adequately sanitize user-supplied input. A command injection attack can be executed if specially crafted parameters are sent. Successful attacks can compromise the affected Web Server and its software.
Mitigation:
Vendor said that the vulnerability was fixed in Development version of 3.2.X branch. However, the fix for 3.1.X branch will be published by June.