Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hxmh-2xc4-c894 | Dolibarr ERP CRM contains a remote code evaluation vulnerability |
Tue, 26 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter. | Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter. |
| Title | Dolibarr ERP CRM 7.0.3 Remote Code Evaluation via install/step1.php | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php |
Sat, 23 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr erp Crm
|
|
| Vendors & Products |
Dolibarr erp Crm
|
Sat, 23 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter. | |
| Title | Dolibarr ERP CRM 7.0.3 Remote Code Evaluation via install/step1.php | |
| First Time appeared |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-26T13:35:57.192Z
Reserved: 2026-05-23T16:27:56.915Z
Link: CVE-2018-25357
Updated: 2026-05-26T13:35:54.194Z
Status : Analyzed
Published: 2026-05-23T19:16:56.033
Modified: 2026-06-17T01:55:18.460
Link: CVE-2018-25357
No data.
OpenCVE Enrichment
Updated: 2026-06-18T02:30:15Z
Github GHSA