← Back to browse · API

CVE-2022-40871

Severity
CRITICAL
CVSS
9.8
EPSS
0.33371
Risk score
50.88
CISA KEV
No
PoC
No
Published
2022-10-12
Modified
2025-05-15
First seen
2026-08-07
Aliases
EUVD-2022-7044, GHSA-7CM4-VMF2-8WF2
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-7044

Description

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

References