CVE-2012-10059
Dolibarr ERP/CRM Post-Auth OS Command Injection
Severity Score
9.4
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the server.
*Credits:
Nahuel Grisolia
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-08-11 CVE Reserved
- 2025-08-13 CVE Published
- 2025-08-14 CVE Updated
- 2025-08-14 First Exploit
- 2025-08-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
- CAPEC-88: OS Command Injection
References (6)
URL | Tag | Source |
---|---|---|
https://www.dolibarr.org | Product | |
https://www.vulncheck.com/advisories/dolibarr-erp-crm-post-auth-os-command-injection | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dolibarr Project Search vendor "Dolibarr Project" | ERP/CRM Search vendor "Dolibarr Project" for product "ERP/CRM" | <= 3.1.1 Search vendor "Dolibarr Project" for product "ERP/CRM" and version " <= 3.1.1" | en |
Affected
| ||||||
Dolibarr Project Search vendor "Dolibarr Project" | ERP/CRM Search vendor "Dolibarr Project" for product "ERP/CRM" | <= 3.2.0 Search vendor "Dolibarr Project" for product "ERP/CRM" and version " <= 3.2.0" | en |
Affected
|