Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-23500

4 месяца назад

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-23500

4 месяца назад

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-23500

4 месяца назад

Dolibarr is an enterprise resource planning (ERP) and customer relatio ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-w5j3-8fcr-h87w

4 месяца назад

Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-23500

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0.

CVSS3: 9.1
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-23500

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0.

CVSS3: 9.1
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-23500

Dolibarr is an enterprise resource planning (ERP) and customer relatio ...

CVSS3: 9.1
1%
Низкий
4 месяца назад
github логотип
GHSA-w5j3-8fcr-h87w

Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration

CVSS3: 9.1
1%
Низкий
4 месяца назад

Уязвимостей на страницу