← Back to browse · API

CVE-2024-5315

Severity
CRITICAL
CVSS
9.1
EPSS
0.34522
Risk score
48.48
CISA KEV
No
PoC
No
Published
2024-05-24
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-1739, GHSA-Q8X7-JC3H-P8XC
Products
Dolibarr:ERP CMS 9.0.1
Sources
euvd EUVD-2024-1739

Description

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

References