{"id":"CVE-2018-25357","aliases":["GHSA-hxmh-2xc4-c894"],"url":"https://o3.security/vulnerability/CVE-2018-25357","summary":"Dolibarr ERP CRM contains a remote code evaluation vulnerability","details":"Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.","published":"2026-05-23T19:16:56.033Z","modified":"2026-08-07T14:59:30.056906Z","cvss":null,"epss":{"score":0.01701,"percentile":0.75248,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"dolibarr/dolibarr","fixedVersion":"7.0.4"},{"ecosystem":"Packagist","name":"dolibarr/dolibarr","fixedVersion":"6.0.8"}],"fix":null,"references":[{"type":"WEB","url":"https://dolibarr.org"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-via-install-step1-php"},{"type":"PACKAGE","url":"https://github.com/Dolibarr/dolibarr"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44964"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:59:30.056906Z"}}