CVE-2024-29477

HIGH

Dolibarr ERP CRM <19.0.0 - Code Injection

Title source: llm
STIX 2.1

Description

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.

Scores

CVSS v3 8.8
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (2)
dolibarr/dolibarr 0Packagist
dolibarr/dolibarr_erp\/crm < 19.0.1
Published Apr 03, 2024
Tracked Since Feb 18, 2026