CVE-2018-13449: SQL Injection
Published Jul 8, 2018
·Updated
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statutbuy parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr=7.0.3
7.0.4
dolibarr Dolibarr Erp\/crm=7.0.3
Remediation
Event History
Jul 8, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-13449?
CVE-2018-13449 is considered a critical SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2018-13449?
To mitigate CVE-2018-13449, upgrade Dolibarr ERP/CRM to version 7.0.4 or later.
3
Which versions of Dolibarr are affected by CVE-2018-13449?
CVE-2018-13449 affects Dolibarr ERP/CRM version 7.0.3.
4
What is the primary attack vector for CVE-2018-13449?
Attackers exploit the CVE-2018-13449 vulnerability through the statut_buy parameter in product/card.php.
5
Can CVE-2018-13449 lead to data loss?
Yes, successful exploitation of CVE-2018-13449 can lead to unauthorized data access and potential data loss.