Skip to content

Dolibarr vulnerable to SQL Injection

Critical severity GitHub Reviewed Published May 24, 2024 to the GitHub Advisory Database • Updated May 24, 2024

Package

composer dolibarr/dolibarr (Composer)

Affected versions

<= 9.0.1

Patched versions

None

Description

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.

References

Published by the National Vulnerability Database May 24, 2024
Published to the GitHub Advisory Database May 24, 2024
Reviewed May 24, 2024
Last updated May 24, 2024

Severity

Critical
9.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CVE ID

CVE-2024-5314

GHSA ID

GHSA-c3h9-q3jx-w7fc

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.