Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Update dolibarr/dolibarr to 7.0.4; dolibarr/dolibarr to 6.0.8 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDolibarr ERP CRM contains a remote code evaluation vulnerability affects dolibarr/dolibarr (composer), dolibarr/dolibarr (composer). Severity is critical. Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| dolibarr/dolibarrcomposer | >=7.0.0,<=7.0.3 | 7.0.4 |
Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
Update dolibarr/dolibarr to 7.0.4; dolibarr/dolibarr to 6.0.8 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDolibarr ERP CRM contains a remote code evaluation vulnerability affects dolibarr/dolibarr (composer), dolibarr/dolibarr (composer). Severity is critical. Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| dolibarr/dolibarrcomposer | >=7.0.0,<=7.0.3 | 7.0.4 |
| dolibarr/dolibarrcomposer | <6.0.8 | 6.0.8 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| dolibarr/dolibarrcomposer | <6.0.8 | 6.0.8 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard