Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxxg-x793-7fq3

Опубликовано: 12 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.php

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

<= 8.0.4

Отсутствует

EPSS

Процентиль: 23%
0.00311
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.2
ubuntu
4 месяца назад

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

CVSS3: 8.2
nvd
4 месяца назад

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

CVSS3: 8.2
debian
4 месяца назад

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the ...

EPSS

Процентиль: 23%
0.00311
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89