First published: Wed Nov 10 2021(Updated: )
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =13.0.2 | |
composer/dolibarr/dolibarr | =13.0.2 | 14.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-33816.
The severity of CVE-2021-33816 is critical with a CVSS score of 9.8.
Dolibarr version 13.0.2 is affected by CVE-2021-33816.
CVE-2021-33816 allows remote PHP code execution due to an incomplete protection mechanism that blocks system, exec, and shell_exec but not backticks.
Yes, references for CVE-2021-33816 are available at the following URLs: [link1](http://seclists.org/fulldisclosure/2021/Nov/39), [link2](https://trovent.github.io/security-advisories/TRSA-2106-01/TRSA-2106-01.txt), [link3](https://trovent.io/security-advisory-2106-01)