CVE-2017-9839: SQL Injection
Published Apr 11, 2018
·Updated
Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<5.0.4
5.0.4
dolibarr Dolibarr Erp\/crm<5.0.4
Event History
Apr 11, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·03:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-9839?
CVE-2017-9839 is classified as a medium severity vulnerability due to its potential to allow SQL injection attacks.
2
How do I fix CVE-2017-9839?
To fix CVE-2017-9839, you should upgrade your Dolibarr ERP/CRM software to version 5.0.4 or later.
3
What versions of Dolibarr ERP/CRM are affected by CVE-2017-9839?
CVE-2017-9839 affects all Dolibarr ERP/CRM versions prior to 5.0.4.
4
What type of vulnerability is CVE-2017-9839?
CVE-2017-9839 is an SQL injection vulnerability located in the product/stats/card.php file.
5
Can CVE-2017-9839 be exploited remotely?
Yes, CVE-2017-9839 can be exploited remotely, allowing attackers to manipulate SQL queries.