T
he admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2018/05/21/2 | Exploit Mailing List Technical Description Third Party Advisory |
| https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Release Notes |
| https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 | Patch |
| https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ | Exploit Technical Description Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2018/05/21/2 | Exploit Mailing List Technical Description Third Party Advisory |
| https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Release Notes |
| https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 | Patch |
| https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ | Exploit Technical Description Third Party Advisory |
Configurations
History
21 Nov 2024, 03:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2018/05/21/2 - Exploit, Mailing List, Technical Description, Third Party Advisory | |
| References | () https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog - Release Notes | |
| References | () https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39 - Patch | |
| References | () https://sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/ - Exploit, Technical Description, Third Party Advisory |
Information
Published : 2018-05-22 20:29
Updated : 2024-11-21 03:40
NVD link : CVE-2018-10092
Mitre link : CVE-2018-10092
CVE.ORG link : CVE-2018-10092
JSON object : View
CWE
CWE-862
Missing Authorization