Vulnerabilities
Vulnerable Software
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
CVSS Score
9.6
EPSS Score
0.03
Published
2023-09-20
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
CVSS Score
8.8
EPSS Score
0.879
Published
2023-05-29
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
CVSS Score
9.8
EPSS Score
0.787
Published
2022-10-12
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
8.4
EPSS Score
0.006
Published
2022-06-13
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-02-25
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-02-23
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
CVSS Score
4.1
EPSS Score
0.003
Published
2022-01-31


Contact Us

Shodan ® - All rights reserved