Dolibarr Erp Crm vulnerabilities
101 known vulnerabilities affecting dolibarr/dolibarr_erp_crm.
Total CVEs
101
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH30MEDIUM49
Vulnerabilities
Page 2 of 6
CVE-2023-38887HIGHCVSS 8.8≤ 17.0.12023-09-20
CVE-2023-38887 [HIGH] CWE-434 CVE-2023-38887: File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execut
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
nvd
CVE-2023-38886HIGHCVSS 7.2≤ 17.0.12023-09-20
CVE-2023-38886 [HIGH] CWE-78 CVE-2023-38886: An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbi
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
nvd
CVE-2023-33568HIGHCVSS 7.5PoC≥ 16.0.0, < 16.0.52023-06-13
CVE-2023-33568 [HIGH] CWE-552 CVE-2023-33568: An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump an
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
nvd
CVE-2023-30253HIGHCVSS 8.8fixed in 17.0.12023-05-29
CVE-2023-30253 [HIGH] CWE-78 CVE-2023-30253: Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipu
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
nvd
CVE-2022-4093CRITICALCVSS 9.8v16.0.1v16.0.22022-11-21
CVE-2022-4093 [CRITICAL] CWE-89 CVE-2022-4093: SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor
nvd
CVE-2022-43138CRITICALCVSS 9.8fixed in 14.0.12022-11-17
CVE-2022-43138 [CRITICAL] CWE-269 CVE-2022-43138: Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges v
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
nvd
CVE-2022-40871CRITICALCVSS 9.8≤ 15.0.32022-10-12
CVE-2022-40871 [CRITICAL] CWE-94 CVE-2022-40871: Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be ad
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
nvd
CVE-2022-2060MEDIUMCVSS 5.4fixed in 16.0.02022-06-13
CVE-2022-2060 [MEDIUM] CWE-79 CVE-2022-2060: Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
nvd
CVE-2022-30875MEDIUMCVSS 6.1v12.0.52022-06-08
CVE-2022-30875 [MEDIUM] CWE-79 CVE-2022-30875: Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
nvd
CVE-2021-37517HIGHCVSS 7.5v13.0.22022-03-31
CVE-2021-37517 [HIGH] CWE-863 CVE-2021-37517: An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the fo
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
nvd
CVE-2021-36625HIGHCVSS 8.8v13.0.22022-03-31
CVE-2021-36625 [HIGH] CWE-89 CVE-2021-36625: An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POS
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
nvd
CVE-2022-0819HIGHCVSS 8.8fixed in 15.0.12022-03-02
CVE-2022-0819 [HIGH] CWE-94 CVE-2022-0819: Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
nvd
CVE-2022-0746MEDIUMCVSS 4.3fixed in 16.0.02022-02-25
CVE-2022-0746 [MEDIUM] CWE-840 CVE-2022-0746: Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
nvd
CVE-2022-0731MEDIUMCVSS 6.5fixed in 16.0.02022-02-23
CVE-2022-0731 [MEDIUM] CWE-284 CVE-2022-0731: Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
nvd
CVE-2022-0414MEDIUMCVSS 4.3fixed in 16.0.02022-01-31
CVE-2022-0414 [MEDIUM] CWE-1284 CVE-2022-0414: Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
nvd
CVE-2022-0224CRITICALCVSS 9.8fixed in 15.0.02022-01-14
CVE-2022-0224 [CRITICAL] CWE-89 CVE-2022-0224: dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
nvd
CVE-2022-0174MEDIUMCVSS 4.3fixed in 15.0.02022-01-10
CVE-2022-0174 [MEDIUM] CWE-1284 CVE-2022-0174: Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
nvd
CVE-2022-22293MEDIUMCVSS 5.4v7.0.22022-01-02
CVE-2022-22293 [MEDIUM] CWE-79 CVE-2022-22293: admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_T
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.
nvd
CVE-2021-33816CRITICALCVSS 9.8v13.0.22021-11-10
CVE-2021-33816 [CRITICAL] CWE-94 CVE-2021-33816: The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incompl
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
nvd
CVE-2021-33618MEDIUMCVSS 6.1v13.0.22021-11-10
CVE-2021-33618 [MEDIUM] CWE-79 CVE-2021-33618: Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
nvd