Dolibarr ERP/CRM Post-Auth OS Command Injection
Vulnerability Description
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10059
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Nahuel Grisolia
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dolibarr_cmd_exec.rb
- https://www.exploit-db.com/exploits/18725
- https://www.exploit-db.com/exploits/18724
- https://seclists.org/fulldisclosure/2012/Apr/78
- https://www.dolibarr.org/
- https://www.vulncheck.com/advisories/dolibarr-erp-crm-post-auth-os-command-injection
Affected Vendor
Dolibarr Project
View all reports →