HIGH
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution
Published Dec 23, 2020
7.2
HIGHCVSS 3.1
EPSS 6.63%
Description
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
Affected products
No data.
- 12.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- http://bilishim.com/2020/12/18/zero-hunting-2.html x_refsource_MISCExploitThird Party Advisory
- https://github.com/Dolibarr/dolibarr/commit/4fcd3fe49332baab0e424225ad10b76b47ebcbac x_refsource_MISCPatchThird Party Advisory
- https://github.com/Dolibarr/dolibarr/releases x_refsource_MISCThird Party Advisory
- https://github.com/advisories/GHSA-7x8g-h246-gvx3 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-35136
- https://sourceforge.net/projects/dolibarr x_refsource_MISCProductThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://bilishim.com/2020/12/18/zero-hunting-2.html | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/Dolibarr/dolibarr/commit/4fcd3fe49332baab0e424225ad10b76b47ebcbac | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/Dolibarr/dolibarr/releases | x_refsource_MISCThird Party Advisory | |
| https://github.com/advisories/GHSA-7x8g-h246-gvx3 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-35136 | ||
| https://sourceforge.net/projects/dolibarr | x_refsource_MISCProductThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 23, 2020
Updated Aug 4, 2024
Reserved Dec 11, 2020
Link CVE-2020-35136
CISA Vulnrichment
GHSA-7X8G-H246-GVX3 Updated n/a