Vulnerabilities
Vulnerable Software
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
CVSS Score
9.6
EPSS Score
0.03
Published
2023-09-20
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
CVSS Score
8.8
EPSS Score
0.879
Published
2023-05-29
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-11-17
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
CVSS Score
9.8
EPSS Score
0.787
Published
2022-10-12
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
8.4
EPSS Score
0.006
Published
2022-06-13
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-03-31
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
CVSS Score
8.8
EPSS Score
0.004
Published
2022-03-31
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
CVSS Score
7.2
EPSS Score
0.035
Published
2022-03-02
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-02-25
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-02-23


Contact Us

Shodan ® - All rights reserved