CVE-2019-25452SQL Injection in ERP CRM

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGHNVD
EPSS
0.1%
top 68.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 22

Description

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract sensitive database information using error-based or time-based blind SQL injection techniques.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
CVE-2019-25452: Dolibarr ERP/CRM 102026-02-22
GHSA
GHSA-ff6v-wx52-q8j8: Dolibarr ERP/CRM 102026-02-22
CVEList
Dolibarr ERP/CRM 10.0.1 SQL Injection via elemid2026-02-22
CVE-2019-25452 — SQL Injection in Dolibarr ERP CRM | cvebase