Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-40871

Опубликовано: 12 окт. 2022
Источник: ubuntu
Приоритет: negligible
EPSS Средний
CVSS3: 9.8

Описание

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

РелизСтатусПримечание
bionic

DNE

esm-apps/xenial

needed

esm-infra/focal

DNE

focal

DNE

jammy

DNE

trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 98%
0.51559
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

CVSS3: 9.8
debian
больше 3 лет назад

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By defaul ...

CVSS3: 9.8
github
больше 3 лет назад

Dolibarr vulnerable to Eval Injection

EPSS

Процентиль: 98%
0.51559
Средний

9.8 Critical

CVSS3