First published: Thu Mar 31 2022(Updated: )
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =13.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-36625 is high with a CVSS score of 8.8.
CVE-2021-36625 affects Dolibarr ERP/CRM version 13.0.2.
The SQL Injection vulnerability in CVE-2021-36625 allows an attacker to execute arbitrary SQL queries, potentially gaining unauthorized access to the database and data manipulation.
Yes, Dolibarr has released a fix for CVE-2021-36625 in version 14.0.0.
To protect your Dolibarr ERP/CRM, update to version 14.0.0 or later, as it contains the necessary security fixes.