CVE-2021-36625: SQL Injection
Published Mar 31, 2022
·Updated
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the countryid parameter in an UPDATE statement.
Affected Software
1 affected component
dolibarr Dolibarr Erp\/crm=13.0.2
Remediation
Event History
Mar 31, 2022
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-36625?
The severity of CVE-2021-36625 is high with a CVSS score of 8.8.
2
How does CVE-2021-36625 affect Dolibarr ERP/CRM?
CVE-2021-36625 affects Dolibarr ERP/CRM version 13.0.2.
3
What is the impact of the SQL Injection vulnerability in CVE-2021-36625?
The SQL Injection vulnerability in CVE-2021-36625 allows an attacker to execute arbitrary SQL queries, potentially gaining unauthorized access to the database and data manipulation.
4
Has Dolibarr released a fix for CVE-2021-36625?
Yes, Dolibarr has released a fix for CVE-2021-36625 in version 14.0.0.
5
How can I protect my Dolibarr ERP/CRM from the SQL Injection vulnerability in CVE-2021-36625?
To protect your Dolibarr ERP/CRM, update to version 14.0.0 or later, as it contains the necessary security fixes.