CVE-2018-9019: SQL Injection
SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categorieslist.php, /accountancy/admin/journalslist.php, /admin/dict.php, /admin/mailstemplates.php, or /admin/website.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/dolibarr/dolibarrto a version that resolves this vulnerability.Fixed in 7.0.2 - Upgrade
Upgrade
Dolibarrto a version that resolves this vulnerability.Fixed in 7.0.2
Event History
Frequently Asked Questions
What is CVE-2018-9019?
CVE-2018-9019 is a SQL Injection vulnerability in Dolibarr before version 7.0.2.
How does CVE-2018-9019 affect Dolibarr?
CVE-2018-9019 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to certain Dolibarr pages.
What is the severity of CVE-2018-9019?
CVE-2018-9019 has a severity level of 9.8 (Critical).
How can I fix CVE-2018-9019 in Dolibarr?
To fix CVE-2018-9019, you should upgrade Dolibarr to version 7.0.2 or above.
Where can I find more information about CVE-2018-9019?
You can find more information about CVE-2018-9019 in the Dolibarr ChangeLog, commit 83b762b681c6dfdceb809d26ce95f3667b614739 on GitHub, and the Oracle Security Alerts.