CVE-2024-5314: Multiple vulnerabilities in DOLIBARR's ERP CMS
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5314?
CVE-2024-5314 is classified as a high severity vulnerability due to its potential to allow SQL injection attacks.
How do I fix CVE-2024-5314?
To fix CVE-2024-5314, upgrade Dolibarr ERP - CRM to version 9.0.2 or later.
What versions of Dolibarr ERP - CRM are affected by CVE-2024-5314?
CVE-2024-5314 affects Dolibarr ERP - CRM version 9.0.1.
What type of attack does CVE-2024-5314 enable?
CVE-2024-5314 enables remote attackers to perform SQL injection, potentially exposing sensitive database information.
Can CVE-2024-5314 be exploited remotely?
Yes, CVE-2024-5314 can be exploited remotely if a specially crafted SQL query is sent to the system.