CVE-2022-40871: Code Injection
Dolibarr ERP & CRM <=15.0.3 are vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
Other sources
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
dolibarr ERP & CRMto a version that resolves this vulnerability.Fixed in 15.0.3
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-40871.
What is the severity of CVE-2022-40871?
The severity of CVE-2022-40871 is critical.
What is the affected software for CVE-2022-40871?
The affected software for CVE-2022-40871 is Dolibarr ERP & CRM version <=15.0.3.
How can an administrator be added to the installation page of Dolibarr?
By default, any administrator can be added to the installation page of Dolibarr.
What can an attacker do if they successfully add an administrator to Dolibarr?
If an attacker successfully adds an administrator to Dolibarr, they can insert malicious code into the database and execute it using 'eval'.