CVE-2024-5314
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published May 24, 2024
CWE ID 89
Summary
CVE-2024-5314 refers to a set of SQL injection vulnerabilities found in Dolibarr ERP - CRM version 9.0.1. These vulnerabilities enable a remote attacker to manipulate the sortorder and sortfield parameters in /dolibarr/admin/dict.php, allowing them to execute malicious SQL queries. Successful exploitation could grant the attacker unauthorized access to all stored data within the database. This poses a significant risk and requires immediate attention from Dolibarr users, who are advised to update their software to a non-vulnerable version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Dolibarr
Affected Vendors
- Dolibarr