Vulnerabilities
Vulnerable Software
Dolibarr:  >> Dolibarr Erp/crm  Security Vulnerabilities
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
CVSS Score
9.8
EPSS Score
0.787
Published
2022-10-12
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
8.4
EPSS Score
0.006
Published
2022-06-13
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
CVSS Score
6.1
EPSS Score
0.003
Published
2022-06-08
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-03-31
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
CVSS Score
8.8
EPSS Score
0.004
Published
2022-03-31
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
CVSS Score
7.2
EPSS Score
0.035
Published
2022-03-02
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-02-25
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-02-23
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
CVSS Score
4.1
EPSS Score
0.003
Published
2022-01-31
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVSS Score
8.3
EPSS Score
0.004
Published
2022-01-14


Contact Us

Shodan ® - All rights reserved