CVE-2019-25710
HIGHDolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25710. PoCs published by Mehmet Onder.
AI-analyzed exploit summary The exploit demonstrates an error-based SQL injection vulnerability in Dolibarr ERP-CRM 8.0.4 via the 'rowid' POST parameter. The payload uses EXTRACTVALUE to trigger an error and leak data, confirming the vulnerability.
Description
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
Exploits (1)
The exploit demonstrates an error-based SQL injection vulnerability in Dolibarr ERP-CRM 8.0.4 via the 'rowid' POST parameter. The payload uses EXTRACTVALUE to trigger an error and leak data, confirming the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N