First published: Wed Apr 11 2018(Updated: )
Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <5.0.4 | 5.0.4 |
Dolibarr ERP & CRM | <5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9839 is classified as a medium severity vulnerability due to its potential to allow SQL injection attacks.
To fix CVE-2017-9839, you should upgrade your Dolibarr ERP/CRM software to version 5.0.4 or later.
CVE-2017-9839 affects all Dolibarr ERP/CRM versions prior to 5.0.4.
CVE-2017-9839 is an SQL injection vulnerability located in the product/stats/card.php file.
Yes, CVE-2017-9839 can be exploited remotely, allowing attackers to manipulate SQL queries.