CVE-2017-17899: SQL Injection
Published Dec 24, 2017
·Updated
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<6.0.5
6.0.5
dolibarr Dolibarr Erp\/crm=6.0.4
Remediation
Event History
Dec 24, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-17899?
CVE-2017-17899 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2017-17899?
To mitigate CVE-2017-17899, upgrade to Dolibarr ERP/CRM version 6.0.5 or later.
3
What software is affected by CVE-2017-17899?
CVE-2017-17899 affects Dolibarr ERP/CRM version 6.0.4.
4
What can attackers exploit in CVE-2017-17899?
Attackers can exploit CVE-2017-17899 to execute arbitrary SQL commands via the rowid parameter.
5
Is CVE-2017-17899 remote or local?
CVE-2017-17899 is a remote vulnerability, allowing attackers to exploit it over the network.