High severity8.0NVD Advisory· Published May 22, 2018· Updated Jun 17, 2026
CVE-2018-10092
CVE-2018-10092
Description
The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | < 7.0.2 | 7.0.2 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/Dolibarr/dolibarr/commit/5d121b2d3ae2a95abebc9dc31e4782cbc61a1f39nvdPatchWEB
- www.openwall.com/lists/oss-security/2018/05/21/2nvdExploitMailing ListTechnical DescriptionThird Party AdvisoryWEB
- sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerability/nvdExploitTechnical DescriptionThird Party Advisory
- github.com/advisories/GHSA-6j62-m2vv-wc3mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-10092ghsaADVISORY
- github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLognvdRelease NotesWEB
- sysdream.com/news/lab/2018-05-21-cve-2018-10092-dolibarr-admin-panel-authenticated-remote-code-execution-rce-vulnerabilityghsaWEB
News mentions
0No linked articles in our index yet.