Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Dolibarr · Dolibarr ERP-CRMpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/46095unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.