Record summary

CVE-2018-25357 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListThrough 7.0.3affected
GitHub Advisory7.0.0 to < 7.0.4 · Fixed in 7.0.4affected
Before 6.0.8 · Fixed in 6.0.8affected

Proofs of concept

1

Catalogued exploits

ExploitDBDolibarr ERP/CRM < 7.0.3 - PHP Code InjectionExploitDB exploitby om3rcitakNot analyzed1 file
ExploitDB

PoC details

References

7