PT-2024-35604 · Unknown · Dolibarr Erp/Crm

Rafael Pedrero

·

Published

2024-05-24

·

Updated

2025-04-10

·

CVE-2024-5314

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr ERP - CRM version 9.0.1
Description The issue allows a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database. This is achieved through the parameters sortorder and sortfield in the "/dolibarr/admin/dict.php" API endpoint.
Recommendations For version 9.0.1, as a temporary workaround, consider restricting access to the "/dolibarr/admin/dict.php" API endpoint to minimize the risk of exploitation. Avoid using the parameters sortorder and sortfield in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2024-5314
CVE-2024-5314
GHSA-C3H9-Q3JX-W7FC

Affected Products

Dolibarr Erp/Crm