CVE-2018-25357
Dolibarr ERP CRM Remote Code Execution via install step1.php.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
Dolibarr ERP/CRM software has a critical vulnerability allowing unauthenticated remote code execution by injecting PHP code through the `db_name` parameter. This could lead to server compromise and impact business operations and sensitive data if the installation or configuration is reachable. Confirmation of affected