Back

HIGH

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution

Published Dec 23, 2020

Description

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 23, 2020
Updated Aug 4, 2024
Reserved Dec 11, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-7X8G-H246-GVX3