Official Product Homepageproduct
https://dolibarr.org/ CVE-2018-25357
CRITICAL
Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php
Record summary
CVE-2018-25357 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Dolibarr ERP CRMBrowse Dolibarr / Dolibarr ERP CRM | CVE List | Through 7.0.3 | affected |
dolibarr/dolibarrBrowse Packagist / dolibarr/dolibarr | GitHub Advisory | 7.0.0 to < 7.0.4 · Fixed in 7.0.4 | affected |
| Before 6.0.8 · Fixed in 6.0.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBDolibarr ERP/CRM < 7.0.3 - PHP Code InjectionExploitDB exploitby om3rcitakNot analyzed1 file
References
7Product Referenceproduct
https://github.com/Dolibarr/dolibarr github.com
https://github.com/Dolibarr/dolibarr/commit/41709f07d0aef384723164877395ed081b44b810 github.com
https://github.com/Dolibarr/dolibarr/issues/9032 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25357 ExploitDB-44964exploit
https://www.exploit-db.com/exploits/44964 VulnCheck Advisory: Dolibarr ERP CRM 7.0.3 Remote Code Evaluation via install/step1.phpThird-party advisory
https://www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-via-install-step1-php