Filtered by vendor Dolibarr Subscriptions
Filtered by product Dolibarr Erp\/crm Subscriptions
Total 102 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2013-2091 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 9.8 Critical
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
CVE-2021-3991 1 Dolibarr 2 Dolibarr, Dolibarr Erp\/crm 2024-11-19 4.3 Medium
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.