Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr dolibarr Erp\/crm
|
|
| CPEs | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Dolibarr dolibarr Erp\/crm
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr
Dolibarr dolibarr Erp/crm |
|
| Vendors & Products |
Dolibarr
Dolibarr dolibarr Erp/crm |
Sun, 22 Feb 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques. | |
| Title | Dolibarr ERP/CRM 10.0.1 SQL Injection via card.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-22T13:18:24.715Z
Updated: 2026-02-25T16:15:57.048Z
Reserved: 2026-02-20T18:37:23.205Z
Link: CVE-2019-25450
Updated: 2026-02-25T16:15:51.628Z
Status : Analyzed
Published: 2026-02-22T14:16:01.990
Modified: 2026-02-25T18:31:13.203
Link: CVE-2019-25450
No data.