Lucene search

K
osvGoogleOSV:GHSA-VXR9-P2XW-M8CF
HistoryMay 24, 2022 - 7:20 p.m.

Dolibarr remote PHP code execution

2022-05-2419:20:28
Google
osv.dev
4
dolibarr
website builder
remote execution

AI Score

7.9

Confidence

Low

EPSS

0.019

Percentile

88.8%

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

AI Score

7.9

Confidence

Low

EPSS

0.019

Percentile

88.8%