Show filters
124 Total Results
Displaying 11-20 of 124
Sort by:
Attacker Value
Unknown

CVE-2023-38888

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Attacker Value
Unknown

CVE-2023-38887

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Attacker Value
Unknown

CVE-2023-38886

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Attacker Value
Unknown

CVE-2023-33568

Disclosure Date: June 13, 2023 (last updated February 25, 2025)
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Attacker Value
Unknown

CVE-2023-30253

Disclosure Date: May 29, 2023 (last updated February 25, 2025)
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Attacker Value
Unknown

CVE-2022-4766

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address this issue. The name of the patch is 082282e9dab43963e6c8f03cfaddd7921de377f4. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216880.
Attacker Value
Unknown

CVE-2022-4093

Disclosure Date: November 21, 2022 (last updated February 24, 2025)
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected
Attacker Value
Unknown

CVE-2022-43138

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
Attacker Value
Unknown

CVE-2022-40871

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
Attacker Value
Unknown

CVE-2022-2060

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.