CVE-2018-19994: SQL Injection
Published Jan 3, 2019
·Updated
An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<8.0.4
8.0.4
dolibarr Dolibarr Erp\/crm=8.0.2
Remediation
Event History
Jan 3, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-19994?
CVE-2018-19994 is classified as a high-severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2018-19994?
To fix CVE-2018-19994, it is recommended to upgrade Dolibarr to version 8.0.4 or later.
3
Who is affected by CVE-2018-19994?
CVE-2018-19994 affects remote authenticated users of Dolibarr version 8.0.2.
4
What type of vulnerability is CVE-2018-19994?
CVE-2018-19994 is an error-based SQL injection vulnerability.
5
What parameter is exploited in CVE-2018-19994?
CVE-2018-19994 exploits the 'desiredstock' parameter in the product/card.php file.