Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6355
HistoryMay 23, 2018 - 2:46 a.m.

SQL Injection

2018-05-2302:46:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

36.3%

dolibarr/dolibarr is vulnerable to SQL injection attacks. The vulnerability exists through the sortfield parameter which affects /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, and /admin/website.php, where it is possible for an arbitrary SQL query to be executed.

EPSS

0.001

Percentile

36.3%