CVE-2018-19998: SQL Injection
Published Jan 3, 2019
·Updated
SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<8.0.4
8.0.4
dolibarr Dolibarr Erp\/crm=8.0.2
Remediation
Event History
Jan 3, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-19998?
CVE-2018-19998 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2018-19998?
To fix CVE-2018-19998, you should update Dolibarr to version 8.0.4 or later.
3
Who is affected by CVE-2018-19998?
CVE-2018-19998 affects remote authenticated users of Dolibarr version 8.0.2.
4
What type of vulnerability is CVE-2018-19998?
CVE-2018-19998 is an SQL injection vulnerability.
5
Can CVE-2018-19998 be exploited remotely?
Yes, CVE-2018-19998 can be exploited remotely by authenticated users.