Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-85108
HistoryApr 01, 2022 - 12:00 a.m.

Dolibarr ERP/CRM SQL Injection Vulnerability (CNVD-2022-85108)

2022-04-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
dolibarr
erp
crm
sql injection
vulnerability
country_id

EPSS

0.001

Percentile

37.0%

Dolibarr ERP/CRM is a web-based enterprise resource planning (ERP) and customer relationship management (CRM) system from the French Dolibarr Foundation. The system can be used to manage products, inventory, invoices, orders, etc. A SQL injection vulnerability exists in Dolibarr ERP/CRM, which stems from the fact that a POST request for the country_id parameter in the UPDATE statement may lead to SQL injection. No detailed vulnerability details are currently available.

EPSS

0.001

Percentile

37.0%