Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-12T00:00:00

Updated: 2024-08-03T12:28:42.656Z

Reserved: 2022-09-19T00:00:00

Link: CVE-2022-40871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-12T12:15:09.657

Modified: 2023-08-08T14:22:24.967

Link: CVE-2022-40871

cve-icon Redhat

No data.