CVE-2017-17900: SQL Injection
Published Dec 24, 2017
·Updated
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<6.0.5
6.0.5
dolibarr Dolibarr Erp\/crm=6.0.4
Remediation
Event History
Dec 24, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-17900?
CVE-2017-17900 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2017-17900?
To fix CVE-2017-17900, upgrade Dolibarr ERP/CRM to version 6.0.5 or later.
3
What are the potential impacts of exploiting CVE-2017-17900?
Exploiting CVE-2017-17900 can allow remote attackers to execute arbitrary SQL commands on the affected system.
4
Which version of Dolibarr is vulnerable to CVE-2017-17900?
Dolibarr ERP/CRM version 6.0.4 is vulnerable to CVE-2017-17900.
5
Is my data safe if I am using a version of Dolibarr after 6.0.5?
If you are using Dolibarr version 6.0.5 or later, your data is not impacted by CVE-2017-17900.