CVE-2024-5315
Multiple vulnerabilities in DOLIBARR's ERP CMS
Record summary
CVE-2024-5315 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 24, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
ERP CMSBrowse Dolibarr / ERP CMSDefault status: unaffected | CVE List | 9.0.1 | affected |
dolibarrBrowse dolibarr / dolibarrDefault status: unknown | CVE List | 9.0.1 | affected |
dolibarr/dolibarrBrowse Packagist / dolibarr/dolibarr | GitHub Advisory | Through 9.0.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALDolibarr ERP CMS `list.php` - SQL InjectionCVSS 9.1
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection.
Impact
These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery