CVE-2025-56588
- EPSS 0.17%
- Veröffentlicht 01.10.2025 20:18:36
- Zuletzt bearbeitet 02.10.2025 19:11:46
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
CVE-2024-34051
- EPSS 1.08%
- Veröffentlicht 03.06.2024 20:15:09
- Zuletzt bearbeitet 21.11.2024 09:17:59
A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.
CVE-2021-42220
- EPSS 0.27%
- Veröffentlicht 15.12.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:25
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
CVE-2021-25957
- EPSS 0.33%
- Veröffentlicht 17.08.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through ...
CVE-2021-25956
- EPSS 0.37%
- Veröffentlicht 17.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account t...
- EPSS 0.42%
- Veröffentlicht 15.08.2021 21:15:06
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. The...
CVE-2021-25954
- EPSS 0.25%
- Veröffentlicht 09.08.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field...
CVE-2020-14209
- EPSS 9.69%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:52
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control ...
CVE-2020-14201
- EPSS 0.15%
- Veröffentlicht 21.08.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:51
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
CVE-2020-14443
- EPSS 0.3%
- Veröffentlicht 18.06.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:03:17
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.