PT-2019-6875 · Dolibarr · Dolibarr Erp/Crm

Alaeddine Mesbahi

+1

·

Published

2019-11-20

·

Updated

2022-11-17

·

CVE-2013-2093

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dolibarr ERP/CRM version 3.3.1
Description The issue arises from improper validation of user input in certain files, allowing remote attackers to execute arbitrary commands. This is specifically related to the viewimage.php and barcode.lib.php files.
Recommendations For Dolibarr ERP/CRM version 3.3.1, consider restricting access to the viewimage.php and barcode.lib.php files until a patch is available. As a temporary workaround, ensure that all user input is thoroughly validated and sanitized to prevent command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2013-2093

Affected Products

Dolibarr Erp/Crm