CVE-2017-7886: SQL Injection
Published May 10, 2017
·Updated
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.
Affected Software
2 affected components
composer/dolibarr/dolibarr=4.0.4
dolibarr Dolibarr Erp\/crm=4.0.4
Event History
May 10, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·02:45 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-7886?
CVE-2017-7886 is classified as a medium severity vulnerability due to its SQL Injection nature.
2
How do I fix CVE-2017-7886?
To mitigate CVE-2017-7886, update Dolibarr ERP/CRM to the latest version that addresses this SQL Injection issue.
3
What systems are affected by CVE-2017-7886?
CVE-2017-7886 specifically affects Dolibarr ERP/CRM version 4.0.4.
4
What type of vulnerability is CVE-2017-7886?
CVE-2017-7886 is an SQL Injection vulnerability found in the Dolibarr ERP/CRM application.
5
What impact does CVE-2017-7886 have on security?
CVE-2017-7886 can allow an attacker to execute arbitrary SQL queries, potentially compromising the database.