CVE-2023-38888
- EPSS 5.01%
- Veröffentlicht 20.09.2023 01:15:56
- Zuletzt bearbeitet 21.11.2024 08:14:23
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScri...
CVE-2023-38887
- EPSS 3.02%
- Veröffentlicht 20.09.2023 01:15:56
- Zuletzt bearbeitet 21.11.2024 08:14:23
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
CVE-2023-38886
- EPSS 48.49%
- Veröffentlicht 20.09.2023 01:15:56
- Zuletzt bearbeitet 21.11.2024 08:14:22
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
CVE-2023-33568
- EPSS 89.26%
- Veröffentlicht 13.06.2023 15:15:14
- Zuletzt bearbeitet 21.11.2024 08:05:44
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
CVE-2023-30253
- EPSS 88.6%
- Veröffentlicht 29.05.2023 21:15:09
- Zuletzt bearbeitet 14.01.2025 17:15:11
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
CVE-2022-4093
- EPSS 0.42%
- Veröffentlicht 21.11.2022 05:15:10
- Zuletzt bearbeitet 21.11.2024 07:34:34
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to...
CVE-2022-2060
- EPSS 0.51%
- Veröffentlicht 13.06.2022 09:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:15
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-30875
- EPSS 0.27%
- Veröffentlicht 08.06.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:31
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
CVE-2021-37517
- EPSS 0.36%
- Veröffentlicht 31.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:17
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
CVE-2021-36625
- EPSS 0.28%
- Veröffentlicht 31.03.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:53
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.