Lucene search

K
osvGoogleOSV:GHSA-FFF9-M6F6-Q3MH
HistoryMay 13, 2022 - 1:11 a.m.

Dolibarr SQL Injection vulnerability

2022-05-1301:11:52
Google
osv.dev
7
dolibarr
sql injection
remote attackers
arbitrary sql commands
accountmodel.php
categories_list.php
journals_list.php
dict.php
mails_templates.php
website.php
security vulnerability

AI Score

8.7

Confidence

Low

EPSS

0.001

Percentile

36.3%

SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.

AI Score

8.7

Confidence

Low

EPSS

0.001

Percentile

36.3%