Description
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Lana Email Logger Cross-Site Scripting (1.0.2)
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.2.8)
Jenkins CVE-2023-44487 Vulnerability (CVE-2023-44487)
WordPress Plugin Travelpayouts:All Travel Brands in One Place Cross-Site Request Forgery (1.0.16)
OpenSSL Improper Input Validation Vulnerability (CVE-2014-3513)