CVE-2020-35136: Command Injection
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilenametemplate parameter to admin/tools/dolibarrexport.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-35136.
What is the severity of CVE-2020-35136?
The severity of CVE-2020-35136 is critical with a CVSS score of 7.2.
How does the vulnerability in Dolibarr 12.0.3 occur?
The vulnerability in Dolibarr 12.0.3 occurs due to a flaw in the backup function of the admin dashboard, which allows an authenticated attacker to execute remote code.
Who can exploit CVE-2020-35136?
An attacker who has access to the admin dashboard in Dolibarr 12.0.3 can exploit CVE-2020-35136.
Is there a fix available for CVE-2020-35136?
Yes, a fix for CVE-2020-35136 is available. It is recommended to update to a patched version of Dolibarr.