FixVibe

critical

Dolibarr ERP CRM Remote Code Evaluation (CVE-2018-25357)

Dolibarr ERP CRM versions before 6.0.8 and 7.0.0 through 7.0.3 are associated with CVE-2018-25357 / GHSA-hxmh-2xc4-c894. FixVibe passive scans flag public Dolibarr deployments that expose an affected version.

CVE-2018-25357GHSA-hxmh-2xc4-c894CWE-94

Dolibarr ERP CRM releases in affected ranges include an installer-related code-evaluation flaw tracked as CVE-2018-25357 / GHSA-hxmh-2xc4-c894. GitHub's reviewed advisory and NVD both associate the issue with critical remote code execution risk in affected releases. [S1] [S2]

Impact

Affected internet-reachable deployments should be prioritized for remediation, especially where legacy installer files or first-run setup paths remain reachable after deployment. A successful attack, according to the public advisories, may allow server-side code execution and could put business data, customer records, and application infrastructure at risk. [S1] [S2]

Affected versions

GitHub's reviewed advisory lists Dolibarr versions before 6.0.8 and 7.0.0 through 7.0.3 as affected. Patched releases include 6.0.8 and 7.0.4. If you maintain a downstream package, appliance image, or vendor-supported fork, verify whether your vendor has backported the fix. [S1]

Covered by FixVibe

FixVibe's passive URL scans flag public Dolibarr deployments that expose an affected version, so you can prioritize the upgrade.

Remediation

Upgrade Dolibarr to 6.0.8, 7.0.4, or a newer supported release, or apply a documented vendor-supported backport. Verify the running version directly on the server or container, remove or restrict installer files after setup, confirm install-lock and configuration-file permissions, keep administration behind trusted-network, VPN, SSO, or authenticated reverse-proxy access, and review web logs if the instance was internet-reachable while affected.