Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dolibarr dolibarr vulnerabilities and exploits
(subscribe to this query)
6
CVSSv2
CVE-2018-10092
The admin panel in Dolibarr prior to 7.0.2 might allow remote malicious users to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.
Dolibarr Dolibarr
7.5
CVSSv2
CVE-2018-10094
SQL injection vulnerability in Dolibarr prior to 7.0.2 allows remote malicious users to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
Dolibarr Dolibarr
1 EDB exploit
4.3
CVSSv2
CVE-2018-19799
Dolibarr ERP/CRM up to and including 8.0.3 has /exports/export.php?datatoexport= XSS.
Dolibarr Dolibarr
6.5
CVSSv2
CVE-2014-7137
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM prior to 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet...
Dolibarr Dolibarr
4.3
CVSSv2
CVE-2015-8685
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.
Dolibarr Dolibarr
6.5
CVSSv2
CVE-2020-12669
core/get_menudiv.php in Dolibarr prior to 11.0.4 allows remote authenticated malicious users to bypass intended access restrictions via a non-alphanumeric menu parameter.
Dolibarr Dolibarr
7.5
CVSSv2
CVE-2019-19212
Dolibarr ERP/CRM 3.0 up to and including 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
Dolibarr Dolibarr
4.3
CVSSv2
CVE-2018-16808
An issue exists in Dolibarr up to and including 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
Dolibarr Dolibarr
7.5
CVSSv2
CVE-2018-16809
An issue exists in Dolibarr up to and including 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
Dolibarr Dolibarr
4
CVSSv2
CVE-2021-25954
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at &ldqu...
Dolibarr Dolibarr
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »