Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6085
HistoryApr 11, 2018 - 6:56 a.m.

SQL Injection

2018-04-1106:56:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.001

Percentile

39.2%

Dolibarr is vulnerable to SQL injection attacks. The attacks exist because it does not properly sanitize the viewstatut and propal_statut(akasearch_statut) parameters in comm/propal/list.php`, allowing the authenticated user to inject arbitrary SQL code through it.

EPSS

0.001

Percentile

39.2%