{"id":"GHSA-vxr9-p2xw-m8cf","summary":"Dolibarr remote PHP code execution","details":"The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.","aliases":["BIT-dolibarr-2021-33816","CVE-2021-33816"],"modified":"2025-04-03T15:27:08.538258Z","published":"2022-05-24T19:20:28Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-24T18:39:36Z","nvd_published_at":"2021-11-10T23:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33816"},{"type":"PACKAGE","url":"https://github.com/Dolibarr/dolibarr"},{"type":"WEB","url":"https://trovent.github.io/security-advisories/TRSA-2106-01/TRSA-2106-01.txt"},{"type":"WEB","url":"https://trovent.io/security-advisory-2106-01"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2021/Nov/39"}],"affected":[{"package":{"name":"dolibarr/dolibarr","ecosystem":"Packagist","purl":"pkg:composer/dolibarr/dolibarr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.0.2"},{"fixed":"14.0.0"}]}],"versions":["13.0.2","13.0.3","13.0.4","13.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vxr9-p2xw-m8cf/GHSA-vxr9-p2xw-m8cf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}