Filtered by vendor Dolibarr
Subscriptions
Total
121 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2017-14238 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter. | ||||
CVE-2017-14239 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php. | ||||
CVE-2017-14242 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter. | ||||
CVE-2017-14241 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php. | ||||
CVE-2017-14240 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter. | ||||
CVE-2017-9838 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and month_end parameters), and don/card.php (societe, lastname, firstname, address, zipcode, town, and email parameters). | ||||
CVE-2017-9839 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter). | ||||
CVE-2017-9840 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application. | ||||
CVE-2017-7887 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter. | ||||
CVE-2017-7886 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter. | ||||
CVE-2017-7888 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. | ||||
CVE-2018-19992 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php. | ||||
CVE-2018-19998 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter. | ||||
CVE-2018-19994 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter. | ||||
CVE-2018-19993 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php. | ||||
CVE-2018-19995 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-08-05 | N/A |
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php. | ||||
CVE-2018-19799 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. | ||||
CVE-2018-16809 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit. | ||||
CVE-2018-16808 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note. | ||||
CVE-2018-10094 | 1 Dolibarr | 1 Dolibarr | 2024-08-05 | N/A |
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes. |