Dolibarr vulnerable to Eval Injection
Critical severity
GitHub Reviewed
Published
Oct 12, 2022
to the GitHub Advisory Database
•
Updated Aug 17, 2023
Description
Published by the National Vulnerability Database
Oct 12, 2022
Published to the GitHub Advisory Database
Oct 12, 2022
Reviewed
Oct 12, 2022
Last updated
Aug 17, 2023
Dolibarr ERP & CRM <=15.0.3 are vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
References