First published: Tue May 22 2018(Updated: )
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr | <7.0.2 | |
composer/dolibarr/dolibarr | <7.0.2 | 7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10094 is a SQL injection vulnerability in Dolibarr before 7.0.2.
CVE-2018-10094 has a severity level of 9.8 (critical).
The affected software is Dolibarr version up to 7.0.2.
Remote attackers can exploit CVE-2018-10094 by executing arbitrary SQL commands via vectors involving integer parameters without quotes.
Yes, you can find more information about CVE-2018-10094 at the following references: [http://www.openwall.com/lists/oss-security/2018/05/21/1](http://www.openwall.com/lists/oss-security/2018/05/21/1), [https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog](https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog), [https://github.com/Dolibarr/dolibarr/commit/7ade4e37f24d6859987bb9f6232f604325633fdd](https://github.com/Dolibarr/dolibarr/commit/7ade4e37f24d6859987bb9f6232f604325633fdd).