#VU31296 SQL injection in dolibarr - CVE-2018-10094
Published: May 22, 2018 / Updated: June 17, 2021
dolibarr
Dolibarr ERP & CRM
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Remediation
External links
- http://www.openwall.com/lists/oss-security/2018/05/21/1
- https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog
- https://github.com/Dolibarr/dolibarr/commit/7ade4e37f24d6859987bb9f6232f604325633fdd
- https://sysdream.com/news/lab/2018-05-21-cve-2018-10094-dolibarr-sql-injection-vulnerability/
- https://www.exploit-db.com/exploits/44805/