Vulnerabilities > CVE-2018-10092 - Missing Authorization vulnerability in Dolibarr

047910
CVSS 8.0 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
dolibarr
CWE-862

Summary

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.

Vulnerable Configurations

Part Description Count
Application
Dolibarr
114

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/147923/dolibarr700-exec.txt
idPACKETSTORM:147923
last seen2018-05-31
published2018-05-27
reporterKevin Locati
sourcehttps://packetstormsecurity.com/files/147923/Dolibarr-7.0.0-Admin-Panel-Remote-Code-Execution.html
titleDolibarr 7.0.0 Admin Panel Remote Code Execution