CVE-2012-10059: Dolibarr ERP/CRM Post-Auth OS Command Injection
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sqlcompat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-10059?
CVE-2012-10059 is classified as a high-severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2012-10059?
To fix CVE-2012-10059, upgrade Dolibarr ERP/CRM to version 3.2.1 or later, which addresses the vulnerability.
What systems are affected by CVE-2012-10059?
CVE-2012-10059 affects Dolibarr ERP/CRM versions 3.1.1 and 3.2.0 or earlier.
What type of vulnerability is CVE-2012-10059?
CVE-2012-10059 is an OS command injection vulnerability found in the database backup feature of Dolibarr ERP/CRM.
Can authenticated users exploit CVE-2012-10059?
Yes, authenticated users can exploit CVE-2012-10059 to inject arbitrary system commands due to insufficient input sanitization.