CVE-2018-10092: High severity dolibarr vulnerability
The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-10092.
What is the severity level of CVE-2018-10092?
CVE-2018-10092 has a severity level of high (8).
How can remote attackers exploit CVE-2018-10092?
Remote attackers can exploit CVE-2018-10092 by leveraging support for updating the antivirus command and parameters used to scan file uploads.
How can I fix CVE-2018-10092?
To fix CVE-2018-10092, upgrade Dolibarr to version 7.0.2 or later.
Where can I find more information about CVE-2018-10092?
You can find more information about CVE-2018-10092 at the following references: [1](http://www.openwall.com/lists/oss-security/2018/05/21/2), [2](https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog), [3](https://github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39).