Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2021-37517
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
0
Attacker Value
Unknown
CVE-2021-36625
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
0
Attacker Value
Unknown
CVE-2021-33816
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
0
Attacker Value
Unknown
CVE-2021-33618
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
0