Server side template injection In dolibarr/dolibarr
Description
Dolibarr remote PHP code execution The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 14.0.0 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.