The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2018/05/21/2 | Exploit Mailing List Technical Description Third Party Advisory |
https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Release Notes |
https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 | Patch |
https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ | Exploit Technical Description Third Party Advisory |
http://www.openwall.com/lists/oss-security/2018/05/21/2 | Exploit Mailing List Technical Description Third Party Advisory |
https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Release Notes |
https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 | Patch |
https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ | Exploit Technical Description Third Party Advisory |
Configurations
History
21 Nov 2024, 03:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2018/05/21/2 - Exploit, Mailing List, Technical Description, Third Party Advisory | |
References | () https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog - Release Notes | |
References | () https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 - Patch | |
References | () https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ - Exploit, Technical Description, Third Party Advisory |
Information
Published : 2018-05-22 20:29
Updated : 2024-11-21 03:40
NVD link : CVE-2018-10092
Mitre link : CVE-2018-10092
CVE.ORG link : CVE-2018-10092
JSON object : View
Products Affected
dolibarr
- dolibarr
CWE
CWE-862
Missing Authorization