First published: Wed Nov 20 2019(Updated: )
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =3.3.1 | |
debian/dolibarr |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-2091 is critical with a CVSS score of 9.8.
The SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands by exploiting the 'pays' parameter in fiche.php.
Dolibarr ERP/CRM version 3.3.1 is affected by CVE-2013-2091.
There are no specific remedies available for CVE-2013-2091.
You can find more information about CVE-2013-2091 on the Debian Security Tracker, Openwall mailing list, and IBM X-Force Exchange.