CVE-2020-35136: Dolibarr Erp/crm
High severity, CVSS 7.2. EPSS: 6.6% chance of exploitation in the next 30 days.
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
Affected products
- Dolibarr Dolibarr Erp/crm: version 12.0.3 only
Published 2020-12-23. Last modified 2026-06-17.