CVE-2019-25710: Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25710?
CVE-2019-25710 is classified as a critical SQL injection vulnerability due to its ability to allow arbitrary SQL queries.
How do I fix CVE-2019-25710?
To mitigate CVE-2019-25710, upgrade to a patched version of Dolibarr ERP-CRM that addresses the rowid parameter vulnerability.
What systems are affected by CVE-2019-25710?
CVE-2019-25710 specifically affects Dolibarr ERP-CRM version 8.0.4.
Can CVE-2019-25710 lead to data exposure?
Yes, CVE-2019-25710 can lead to unauthorized data exposure through injected SQL queries.
What are the potential impacts of CVE-2019-25710?
The potential impacts of CVE-2019-25710 include data manipulation, unauthorized access, and overall loss of data integrity.