Description
Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
Credits
om3rcitak - https://omercitak.com
References
www.exploit-db.com/exploits/44964 (ExploitDB-44964)
dolibarr.org (Official Product Homepage)
github.com/Dolibarr/dolibarr (Product Reference)
www.vulncheck.com/...e-code-evaluation-via-install-step1-php (VulnCheck Advisory: Dolibarr ERP CRM 7.0.3 Remote Code Evaluation via install/step1.php)