CVE-2022-40871Code Injection in ERP CRM

Severity
9.8CRITICALNVD
EPSS
51.6%
top 2.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 12

Description

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Packagistdolibarr/dolibarr15.0.3

🔴Vulnerability Details

4
CVEList
CVE-2022-40871: Dolibarr ERP & CRM <=152022-10-12
OSV
Dolibarr vulnerable to Eval Injection2022-10-12
GHSA
Dolibarr vulnerable to Eval Injection2022-10-12
OSV
CVE-2022-40871: Dolibarr ERP & CRM <=152022-10-12
CVE-2022-40871 — Code Injection in Dolibarr ERP CRM | cvebase