Lucene search

K
osvGoogleOSV:GHSA-H34Q-878W-W96R
HistoryMay 14, 2022 - 1:27 a.m.

Dolibarr SQL injection via the integer parameters qty and value_unit

2022-05-1401:27:09
Google
osv.dev
4
dolibarr
sql injection
integer parameters
expense reports
software

AI Score

7.8

Confidence

Low

EPSS

0.002

Percentile

59.4%

An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.

AI Score

7.8

Confidence

Low

EPSS

0.002

Percentile

59.4%