CVE-2018-10092

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:40

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2018/05/21/2 - Exploit, Mailing List, Technical Description, Third Party Advisory () http://www.openwall.com/lists/oss-security/2018/05/21/2 - Exploit, Mailing List, Technical Description, Third Party Advisory
References () https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog - Release Notes () https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog - Release Notes
References () https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 - Patch () https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 - Patch
References () https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ - Exploit, Technical Description, Third Party Advisory () https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ - Exploit, Technical Description, Third Party Advisory

Information

Published : 2018-05-22 20:29

Updated : 2024-11-21 03:40


NVD link : CVE-2018-10092

Mitre link : CVE-2018-10092

CVE.ORG link : CVE-2018-10092


JSON object : View

Products Affected

dolibarr

  • dolibarr
CWE
CWE-862

Missing Authorization