CVE-2019-19211
- EPSS 2.1%
- Veröffentlicht 16.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:20
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
CVE-2019-19210
- EPSS 0.61%
- Veröffentlicht 16.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:20
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
CVE-2019-19209
- EPSS 1.56%
- Veröffentlicht 16.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:20
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
CVE-2018-16809
- EPSS 0.71%
- Veröffentlicht 07.03.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:23
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
CVE-2018-16808
- EPSS 0.2%
- Veröffentlicht 07.03.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:23
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
CVE-2018-19799
- EPSS 2.18%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:58:35
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
CVE-2018-9019
- EPSS 2%
- Veröffentlicht 22.05.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:14:47
SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/jour...
CVE-2018-10095
- EPSS 47.5%
- Veröffentlicht 22.05.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:48
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
CVE-2018-10094
- EPSS 73.71%
- Veröffentlicht 22.05.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:48
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
- EPSS 0.43%
- Veröffentlicht 22.05.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:48
The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.