Vulnerabilities
Vulnerable Software
Dolibarr:  >> Dolibarr Erp/crm  Security Vulnerabilities
Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.
CVSS Score
6.1
EPSS Score
0.01
Published
2019-07-15
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.
CVSS Score
6.1
EPSS Score
0.014
Published
2019-01-03
An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.
CVSS Score
8.8
EPSS Score
0.02
Published
2019-01-03
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.
CVSS Score
5.4
EPSS Score
0.011
Published
2019-01-03
SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.
CVSS Score
8.8
EPSS Score
0.022
Published
2019-01-03
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.
CVSS Score
5.4
EPSS Score
0.011
Published
2019-01-03
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter.
CVSS Score
9.8
EPSS Score
0.019
Published
2018-07-08
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.
CVSS Score
9.8
EPSS Score
0.019
Published
2018-07-08
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter.
CVSS Score
9.8
EPSS Score
0.019
Published
2018-07-08
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter.
CVSS Score
9.8
EPSS Score
0.019
Published
2018-07-08


Contact Us

Shodan ® - All rights reserved