Dolibarr

Dolibarr Erp/crm

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 79.34%
  • Veröffentlicht 29.05.2023 21:15:09
  • Zuletzt bearbeitet 14.01.2025 17:15:11

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

Exploit
  • EPSS 3.95%
  • Veröffentlicht 21.11.2022 05:15:10
  • Zuletzt bearbeitet 21.11.2024 07:34:34

SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 13.06.2022 09:15:10
  • Zuletzt bearbeitet 21.11.2024 07:00:15

Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.

  • EPSS 0.67%
  • Veröffentlicht 08.06.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:31

Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

  • EPSS 0.99%
  • Veröffentlicht 31.03.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:15:17

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

  • EPSS 0.93%
  • Veröffentlicht 31.03.2022 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:53

An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

Exploit
  • EPSS 41.01%
  • Veröffentlicht 02.03.2022 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:39:27

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

Exploit
  • EPSS 0.88%
  • Veröffentlicht 25.02.2022 09:15:06
  • Zuletzt bearbeitet 21.11.2024 06:39:18

Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 23.02.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:39:16

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 31.01.2022 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:38:34

Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.