Dolibarr ERP & CRM
cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*, +1 more
- 21.0.1
A remote code execution vulnerability has been identified in Dolibarr ERP & CRM version 21.0.1. The issue arises in the User module's configuration of computed fields, where improperly handled expressions can be exploited to execute server-side code. This vulnerability allows authenticated administrators to create or modify computed fields that, when evaluated during page rendering, bypass previous security fixes and execute malicious code on the server.
Exploitation of this vulnerability allows for arbitrary code execution on the server.
Users can apply the patch available in the Dolibarr GitHub repository, specifically in the commit linked in the references.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.