Laurent Destailleur
62 exploits
Active since Dec 2011
Dolibarr ERP CRM Legacy Filemanager config.inc.php improper authorization
CVSS 6.3
Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization
CVSS 4.3
Dolibarr ERP CRM messaging.php authorization
CVSS 4.3
Dolibarr <=22.0.2 User Extrafields - Authenticated Code Execution
CVSS 7.2
Dolibarr < 3.1.0 - Authenticated SQL Injection via Multiple Parameters
Dolibarr < 3.1.0 - Cross-Site Scripting via PATH_INFO and optioncss Parameter
Dolibarr < 3.1.0 - Authenticated SQL Injection via Multiple Parameters
Dolibarr < 3.1.0 - Cross-Site Scripting via PATH_INFO and optioncss Parameter
Dolibarr < 3.1.0 - Authenticated SQL Injection via Multiple Parameters
Dolibarr < 3.1.0 - Cross-Site Scripting via PATH_INFO and optioncss Parameter
awstats < 7.6.0 - Unauthenticated Path Traversal and Remote Code Execution via Config and Migrate Parameters
CVSS 9.8
Dolibarr ERP/CRM 6.0.4 - Exposure of Sensitive Information via Direct TPL.PHP File Access
CVSS 7.5
Dolibarr < 7.0.2 - SQL Injection via Integer Parameter
CVSS 9.8
Dolibarr < 8.0.4 - Authenticated Stored Cross-Site Scripting via User Address or Town Parameter
CVSS 5.4
Dolibarr 8.0.2 - Authenticated SQL Injection via Employee Parameter
CVSS 8.8
Dolibarr 16.0.0-16.0.4 - Unauthenticated Database Dump via Contact File Access
CVSS 7.5
Dolibarr ERP CRM <= 18.0.1 - Remote Code Execution via Website Input
CVSS 7.5
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
CVSS 7.2
Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php
CVSS 6.5
Dolibarr ERP/CRM 3.3.1 - Cross-Site Scripting in functions.lib.php
CVSS 6.1
Dolibarr ERP/CRM 3.3.1 - Remote Code Execution via viewimage.php and barcode.lib.php
CVSS 9.8
awstats < 7.6.0 - Unauthenticated Path Traversal and Remote Code Execution via Config and Migrate Parameters
CVSS 9.8
Dolibarr ERP/CRM <6.0.0 - SQL Injection
CVSS 9.8
Dolibarr 6.0.0 - Authenticated Cross-Site Scripting via Company Profile Parameters
CVSS 5.4
Dolibarr ERP/CRM <6.0.0 - Info Disclosure
CVSS 7.5