Record summary

CVE-2024-5315 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 24, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List9.0.1affected

Default status: unknown

CVE List9.0.1affected
GitHub AdvisoryThrough 9.0.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALDolibarr ERP CMS `list.php` - SQL InjectionCVSS 9.1

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection.

Impact

These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-89
Authorsrootxharsh, iamnoooob, pdresearch
Template tagscvecve2024dolibarrerpsqliauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:dolibarr:dolibarr_erp\\/crm:*:*:*:*:*:*:*:*
Shodan: http.title:"Dolibarr"

Source: ProjectDiscovery

References

3