CVE-2022-40871
Publication date 12 October 2022
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
Status
Package | Ubuntu Release | Status |
---|---|---|
dolibarr | 22.04 LTS jammy | Not in release |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial |
Vulnerable
|
|
14.04 LTS trusty | Ignored |
Notes
rodrigo-zaiden
dolibarr was removed from Debian in 2018 and Ubuntu latest version is for Xenial, based on 3.5.8+dfsg1. more info can be found in: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=890598
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 · Critical |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |