CVE-2019-25710

HIGH

Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25710. PoCs published by Mehmet Onder.

AI-analyzed exploit summary The exploit demonstrates an error-based SQL injection vulnerability in Dolibarr ERP-CRM 8.0.4 via the 'rowid' POST parameter. The payload uses EXTRACTVALUE to trigger an error and leak data, confirming the vulnerability.

Description

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

Exploits (1)

exploitdb WORKING POC
by Mehmet Onder · textwebappsphp
https://www.exploit-db.com/exploits/46095

The exploit demonstrates an error-based SQL injection vulnerability in Dolibarr ERP-CRM 8.0.4 via the 'rowid' POST parameter. The payload uses EXTRACTVALUE to trigger an error and leak data, confirming the vulnerability.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Dolibarr ERP-CRM v8.0.4
Auth required
Prerequisites: access to the admin/dict.php endpoint · valid session token
devstral-2 · analyzed Apr 12, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46095
https://www.exploit-db.com/exploits/46095
Product product
Official Product Homepage
https://www.dolibarr.org/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
https://www.vulncheck.com/advisories/dolibarr-erp-crm-sql-injection-via-rowid-parameter

Scores

CVSS v3 8.2
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (3)
dolibarr/dolibarr 0Packagist
Dolibarr/Dolibarr ERP-CRM 8.0.4
dolibarr/dolibarr_erp\/crm < 8.0.4
Published Apr 12, 2026
Tracked Since Apr 12, 2026