CVE-2017-14242: SQL Injection
Published Sep 11, 2017
·Updated
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<6.0.1
6.0.1
dolibarr Dolibarr=6.0.0
Remediation
Event History
Sep 11, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
May 17, 2022
Advisory Published
via GitHub·01:05 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-14242?
CVE-2017-14242 has been classified as a medium severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2017-14242?
To fix CVE-2017-14242, upgrade Dolibarr from version 6.0.0 to version 6.0.1 or later.
3
What software is affected by CVE-2017-14242?
CVE-2017-14242 affects Dolibarr version 6.0.0.
4
What attack vector is exploited in CVE-2017-14242?
CVE-2017-14242 is exploited via the statut parameter in the don/list.php script.
5
Can CVE-2017-14242 be exploited remotely?
Yes, CVE-2017-14242 allows remote attackers to execute arbitrary SQL commands.