PT-2019-9961 · Dolibarr · Dolibarr

·

CVE-2018-19998

·

Published

2019-01-03

·

Updated

2022-11-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr version 8.0.2
Description A SQL injection issue allows remote authenticated users to execute arbitrary SQL commands via the employee parameter in the user/card.php file.
Recommendations For Dolibarr version 8.0.2, consider restricting access to the user/card.php file until a patch is available. As a temporary workaround, avoid using the employee parameter in the affected file to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19998
GHSA-97JV-2HP6-3FRJ

Affected Products

Dolibarr