Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3h9-q3jx-w7fc

Опубликовано: 24 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Dolibarr vulnerable to SQL Injection

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

<= 9.0.1

Отсутствует

EPSS

Процентиль: 43%
0.00208
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 1 года назад

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.

CVSS3: 9.1
nvd
больше 1 года назад

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.

CVSS3: 9.1
debian
больше 1 года назад

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and al ...

EPSS

Процентиль: 43%
0.00208
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-89