Description
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
Remediation
References
Related Vulnerabilities
WordPress CVE-2012-2399 Vulnerability (CVE-2012-2399)
WordPress Plugin WP Database Reset Multiple Security Bypass Vulnerabilities (3.1)
Nginx Integer Overflow or Wraparound Vulnerability (CVE-2017-20005)
WordPress Plugin Social Media Widget by Acurax Multiple Unspecified Vulnerabilities (3.2.3)
WordPress Plugin Import and export users and customers CSV Injection (1.16.3.5)