CVE-2018-25357
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 1.70%
- 75th pct
- KEV
- No
- Class
- oss containerizable
- CWE-94
Description
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Affected packages
| Packagist | dolibarr/dolibarr | 0 → 6.0.8 |
| Packagist | dolibarr/dolibarr | 7.0.0 → 7.0.4 |
References
Status: profiled · ingested 2026-07-23T18:00:18.000Z