CVE-2018-16809: SQL Injection
Published Mar 7, 2019
·Updated
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and valueunit.
Affected Software
2 affected components
composer/dolibarr/dolibarr>=3.8<=7.0.0
dolibarr Dolibarr>=3.8.0<=7.0.0
Event History
Mar 7, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:27 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16809.
2
What is the severity of CVE-2018-16809?
The severity of CVE-2018-16809 is critical with a severity value of 9.8.
3
How does the vulnerability in Dolibarr through 7.0.0 allow SQL injection?
The vulnerability in Dolibarr through 7.0.0 allows SQL injection via the integer parameters qty and value_unit in the expense reports module.
4
What is the affected software for CVE-2018-16809?
The affected software for CVE-2018-16809 is Dolibarr version 3.8.0 through 7.0.0.
5
Is there a patch available for fixing the vulnerability in Dolibarr?
Yes, you can find more information about the patch for fixing the vulnerability in Dolibarr at the reference link provided.