SQL Injection Vulnerability in Dolibarr ERP/CRM by Dolibarr
CVE-2021-36625

8.8HIGH

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
31 March 2022

What is CVE-2021-36625?

Dolibarr ERP/CRM versions prior to 14.0.0 are susceptible to an SQL Injection vulnerability, which arises from improper handling of the country_id parameter within an UPDATE statement via POST requests. This security flaw could potentially enable unauthorized users to manipulate database queries, leading to data exposure or modification.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.