Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. dolibarr/dolibarr
  4. ›
  5. CVE-2018-25357

CVE-2018-25357: Dolibarr ERP CRM contains a remote code evaluation vulnerability

May 26, 2026 (updated June 30, 2026)

Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.

References

  • dolibarr.org/
  • github.com/Dolibarr/dolibarr
  • github.com/Dolibarr/dolibarr/commit/41709f07d0aef384723164877395ed081b44b810
  • github.com/Dolibarr/dolibarr/issues/9032
  • github.com/advisories/GHSA-hxmh-2xc4-c894
  • nvd.nist.gov/vuln/detail/CVE-2018-25357
  • www.exploit-db.com/exploits/44964
  • www.vulncheck.com/advisories/dolibarr-erp-crm-remote-code-evaluation-via-install-step1-php

Code Behaviors & Features

Detect and mitigate CVE-2018-25357 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 6.0.8, all versions starting from 7.0.0 before 7.0.4

Fixed versions

  • 6.0.8
  • 7.0.4

Solution

Upgrade to versions 6.0.8, 7.0.4 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

packagist/dolibarr/dolibarr/CVE-2018-25357.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 21 Jul 2026 00:19:17 +0000.