Description
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Flipbox Builder PHP Object Injection (1.5)
PHP Improper Input Validation Vulnerability (CVE-2011-4885)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1432)
WordPress Ultimate Member Plugin CVE-2020-36170 Vulnerability (CVE-2020-36170)
Multiple SugarCRM Products Remote Code Execution Vulnerability (CVE-2023-22952)