CVE-2017-14238: SQL Injection
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14238?
CVE-2017-14238 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2017-14238?
To fix CVE-2017-14238, upgrade to Dolibarr version 6.0.1 or later, which addresses the SQL injection vulnerability.
What are the potential impacts of CVE-2017-14238?
The potential impacts of CVE-2017-14238 include unauthorized access to the database, data corruption, and exposure of sensitive information due to SQL injection.
Which versions of Dolibarr are affected by CVE-2017-14238?
CVE-2017-14238 affects Dolibarr ERP/CRM version 6.0.0.
Is there a workaround for CVE-2017-14238?
There are no official workarounds for CVE-2017-14238, and it is recommended to apply the software update to mitigate the risk.