Looking for the vulnerability index of Invicti's legacy products?
Dolibarr Incorrect Default Permissions Vulnerability (CVE-2022-40871) - Vulnerability Database

Dolibarr Incorrect Default Permissions Vulnerability (CVE-2022-40871)

Description

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

References

Related Vulnerabilities