Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-3992. PoCs published by Deepak Rathore.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Dolibarr's user management and group index pages, with proof-of-concept payloads for the 'entity' and 'sortorder' parameters. It also includes a Cross-Site Request Forgery (CSRF) vulnerability via link injection in the 'dol_hide_leftmenu' parameter.
Description
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Dolibarr's user management and group index pages, with proof-of-concept payloads for the 'entity' and 'sortorder' parameters. It also includes a Cross-Site Request Forgery (CSRF) vulnerability via link injection in the 'dol_hide_leftmenu' parameter.