Description
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Add Link to Facebook Cross-Site Scripting (2.2.7)
WordPress Plugin WP-Syntax Remote PHP Code Execution (0.9.9)
WordPress Plugin Multi Feed Reader Multiple Vulnerabilities (2.2.4)
Apache HTTP Server Out-of-bounds Read Vulnerability (CVE-2021-36160)
WordPress Plugin Brizy-Page Builder Cross-Site Scripting (2.3.26)