Description
An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2953 | An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter. |
Github GHSA |
GHSA-78hj-952q-99rw | Dolibarr error-based SQL injection vulnerability in product/card.php |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:51:18.066Z
Reserved: 2018-12-09T00:00:00.000Z
Link: CVE-2018-19994
No data.
Status : Modified
Published: 2019-01-03T19:29:01.053
Modified: 2024-11-21T03:58:57.827
Link: CVE-2018-19994
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA