9.8
CVSSv3

CVE-2018-10094

Published: 22/05/2018 Updated: 02/07/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Dolibarr prior to 7.0.2 allows remote malicious users to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr

Exploits

# [CVE-2018-10094] Dolibarr SQL Injection vulnerability ## Description Dolibarr is an "Open Source ERP & CRM for Business" used by many companies worldwide It is available through [GitHub](githubcom/Dolibarr/dolibarr) or as distribution packages (eg deb package) **Threat** The application does not handle user input properly a ...
Dolibarr version 700 suffers from a remote SQL injection vulnerability ...