Show filters
123 Total Results
Displaying 11-20 of 123
Sort by:
Attacker Value
Unknown

CVE-2023-38886

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Attacker Value
Unknown

CVE-2023-33568

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Attacker Value
Unknown

CVE-2023-30253

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Attacker Value
Unknown

CVE-2022-4933

Disclosure Date: March 20, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version 1.1.7 is able to address this issue. The patch is identified as ccad1e4282b0e393a32fcc852e82ec0e0af5446f. It is recommended to upgrade the affected component. VDB-223382 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-4766

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address this issue. The name of the patch is 082282e9dab43963e6c8f03cfaddd7921de377f4. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216880.
Attacker Value
Unknown

CVE-2022-4093

Disclosure Date: November 21, 2022 (last updated December 22, 2024)
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected
Attacker Value
Unknown

CVE-2022-43138

Disclosure Date: November 17, 2022 (last updated December 22, 2024)
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
Attacker Value
Unknown

CVE-2022-40871

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
Attacker Value
Unknown

CVE-2022-2060

Disclosure Date: June 13, 2022 (last updated November 29, 2024)
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
Attacker Value
Unknown

CVE-2022-30875

Disclosure Date: June 08, 2022 (last updated November 08, 2023)
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.