The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
References
Link | Resource |
---|---|
https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ | Exploit Technical Description Third Party Advisory |
https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 | Patch |
https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Release Notes |
http://www.openwall.com/lists/oss-security/2018/05/21/2 | Exploit Mailing List Technical Description Third Party Advisory |
Configurations
Information
Published : 2018-05-22 13:29
Updated : 2020-08-24 10:37
NVD link : CVE-2018-10092
Mitre link : CVE-2018-10092
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
dolibarr
- dolibarr