SQL Injection Vulnerability in Dolibarr ERP/CRM by Dolibarr
CVE-2021-36625
8.8HIGH
What is CVE-2021-36625?
Dolibarr ERP/CRM versions prior to 14.0.0 are susceptible to an SQL Injection vulnerability, which arises from improper handling of the country_id parameter within an UPDATE statement via POST requests. This security flaw could potentially enable unauthorized users to manipulate database queries, leading to data exposure or modification.