Description
Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).
Remediation
References
Related Vulnerabilities
WordPress Plugin Adminer Cross-Site Scripting (1.4.2)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-20502)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2606)
WordPress Plugin Protected Posts Logout Button Security Bypass (1.4.5)