CVE-2018-10094

CRITICAL

Dolibarr <7.0.2 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Sysdream · textwebappsphp
https://www.exploit-db.com/exploits/44805
metasploit WORKING POC
by Issam Rabhi, Kevin Locati, Shelby Pace · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/dolibarr_creds_sqli.rb

Scores

CVSS v3 9.8
EPSS 0.7371
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
dolibarr/dolibarr < 7.0.2
dolibarr/dolibarr 0 - 7.0.2Packagist
Published May 22, 2018
Tracked Since Feb 18, 2026