Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the server.
Metrics
Affected Vendors & Products
References
History
Sat, 16 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dolibarr
Dolibarr dolibarr Dolibarr dolibarr Erp/crm |
|
Vendors & Products |
Dolibarr
Dolibarr dolibarr Dolibarr dolibarr Erp/crm |
Thu, 14 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the server. | |
Title | Dolibarr ERP/CRM Post-Auth OS Command Injection | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-13T20:33:50.619Z
Updated: 2025-08-14T14:21:38.227Z
Reserved: 2025-08-11T19:34:12.437Z
Link: CVE-2012-10059

Updated: 2025-08-14T14:21:28.893Z

Status : Awaiting Analysis
Published: 2025-08-13T21:15:30.453
Modified: 2025-08-14T15:15:31.170
Link: CVE-2012-10059

No data.