RSS   Vulnerabilities for 'Dolibarr'   RSS

2019-03-07
 
CVE-2018-16809

CWE-89
 

 
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.

 
 
CVE-2018-16808

CWE-79
 

 
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

 
2019-01-03
 
CVE-2018-19998

CWE-89
 

 
SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.

 
 
CVE-2018-19995

CWE-79
 

 
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

 
 
CVE-2018-19994

CWE-89
 

 
An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.

 
 
CVE-2018-19993

CWE-79
 

 
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

 
 
CVE-2018-19992

CWE-79
 

 
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

 
2018-12-26
 
CVE-2018-19799

CWE-79
 

 
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.

 
2018-07-08
 
CVE-2018-13447

CWE-89
 

 
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

 
2018-05-22
 
CVE-2018-9019

CWE-89
 

 
SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.

 


Copyright 2019, cxsecurity.com

 

Back to Top