Critical severity9.8NVD Advisory· Published May 23, 2026· Updated Jul 23, 2026
CVE-2018-25357
CVE-2018-25357
Description
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | >= 7.0.0, < 7.0.4 | 7.0.4 |
dolibarr/dolibarrPackagist | < 6.0.8 | 6.0.8 |
Affected products
2Patches
Vulnerability mechanics
References
7- www.exploit-db.com/exploits/44964nvdExploitVDB EntryWEB
- github.com/advisories/GHSA-hxmh-2xc4-c894ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-25357ghsaADVISORY
- www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-via-install-step1-phpnvdThird Party AdvisoryWEB
- dolibarr.orgnvdProductWEB
- github.com/Dolibarr/dolibarr/commit/41709f07d0aef384723164877395ed081b44b810ghsaWEB
- github.com/Dolibarr/dolibarr/issues/9032ghsaWEB
News mentions
0No linked articles in our index yet.