First published: Mon Nov 21 2022(Updated: )
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =16.0.1 | |
Dolibarr Dolibarr Erp\/crm | =16.0.2 | |
=16.0.1 | ||
=16.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4093 is a vulnerability that allows SQL injection attacks, resulting in unauthorized access to sensitive data.
CVE-2022-4093 affects Dolibarr ERP/CRM versions 16.0.1 and 16.0.2.
CVE-2022-4093 has a severity rating of 9.8 (Critical).
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information.
To fix the CVE-2022-4093 vulnerability in Dolibarr ERP/CRM, you should update to a version that includes the necessary security patches.