Vulnerabilities > CVE-2018-10092 - Missing Authorization vulnerability in Dolibarr

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.

Vulnerable Configurations

Part Description Count
Application
Dolibarr
112

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/147923/dolibarr700-exec.txt
idPACKETSTORM:147923
last seen2018-05-31
published2018-05-27
reporterKevin Locati
sourcehttps://packetstormsecurity.com/files/147923/Dolibarr-7.0.0-Admin-Panel-Remote-Code-Execution.html
titleDolibarr 7.0.0 Admin Panel Remote Code Execution