PT-2019-9959 · Dolibarr · Dolibarr

·

CVE-2018-19994

·

Published

2019-01-03

·

Updated

2022-11-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr version 8.0.2
Description The issue is related to an error-based SQL injection, allowing remote authenticated users to execute arbitrary SQL commands. This is achieved by manipulating the desiredstock parameter in the product/card.php file.
Recommendations For Dolibarr version 8.0.2, consider restricting access to the product/card.php file until a patch is available, and avoid using the desiredstock parameter in this context to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19994
GHSA-78HJ-952Q-99RW

Affected Products

Dolibarr