Description
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2001-1385)
Apache Tomcat Other Vulnerability (CVE-2008-0002)
WordPress Plugin Js-appointment 'searchdata.php' SQL Injection (1.5)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5318)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-11327)