First published: Tue Feb 21 2012(Updated: )
Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr ERP & CRM | <=3.2.0 | |
Dolibarr ERP & CRM | =2.5.0 | |
Dolibarr ERP & CRM | =2.6.0 | |
Dolibarr ERP & CRM | =2.6.1 | |
Dolibarr ERP & CRM | =2.7.0 | |
Dolibarr ERP & CRM | =2.7.1 | |
Dolibarr ERP & CRM | =2.8.0 | |
Dolibarr ERP & CRM | =2.8.1 | |
Dolibarr ERP & CRM | =2.9.0 | |
Dolibarr ERP & CRM | =3.0.0 | |
Dolibarr ERP & CRM | =3.0.1 | |
Dolibarr ERP & CRM | =3.1.0 | |
Dolibarr ERP & CRM | =3.1.0-rc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1225 is considered to have a high severity due to its potential for remote SQL injection by authenticated users.
To fix CVE-2012-1225, upgrade to a version of Dolibarr CMS that is higher than 3.2.0 Alpha.
CVE-2012-1225 affects Dolibarr CMS versions 3.2.0 Alpha and earlier, as well as specific later versions up to 3.1.0-rc.
No, CVE-2012-1225 can only be exploited by remote authenticated users.
CVE-2012-1225 allows for arbitrary SQL commands to be executed via the memberslist and rowid parameters.