Back

CRITICAL

Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php

Published May 23, 2026

Description

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 23, 2026
Updated May 26, 2026
Reserved May 23, 2026
CISA Vulnrichment
Updated May 26, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-HXMH-2XC4-C894