CVE-2018-10092: Dolibarr

High severity, CVSS 8.0. EPSS: 2% chance of exploitation in the next 30 days.

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.

Affected products

  • Dolibarr Dolibarr: before 7.0.2 (fixed in 7.0.2)

Published 2018-05-22. Last modified 2026-06-17.