Remote Code Execution Vulnerability in Dolibarr ERP CRM by Dolibarr
CVE-2018-25357
Key Information:
- Vendor
Dolibarr
- Status
- Vendor
- CVE Published:
- 23 May 2026
Badges
What is CVE-2018-25357?
Dolibarr ERP CRM 7.0.3 is susceptible to a remote code execution vulnerability that enables unauthenticated attackers to inject and execute arbitrary PHP code via the db_name parameter. By sending a controlled POST request to install/step1.php, attackers can manipulate the application to execute commands through check.php using the cmd GET parameter. This vulnerability poses serious security risks to systems using this version of Dolibarr, allowing potential unauthorized control over the affected system.
Affected Version(s)
Dolibarr ERP CRM 0 <= 7.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
