CVE-2017-17897: SQL Injection
Published Dec 24, 2017
·Updated
SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<6.0.5
6.0.5
dolibarr Dolibarr Erp\/crm=6.0.4
Remediation
Event History
Dec 24, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-17897?
CVE-2017-17897 is considered a critical SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2017-17897?
To fix CVE-2017-17897, upgrade Dolibarr ERP/CRM to version 6.0.5 or later.
3
Which versions are affected by CVE-2017-17897?
CVE-2017-17897 affects Dolibarr ERP/CRM version 6.0.4.
4
What type of vulnerability is CVE-2017-17897?
CVE-2017-17897 is an SQL injection vulnerability.
5
Can CVE-2017-17897 lead to data breaches?
Yes, CVE-2017-17897 can lead to unauthorized access and potential data breaches due to arbitrary SQL command execution.