PoC Index

CVE-2011-4802

MEDIUM 6.5EPSS 5.5%

Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
5.46% chance of exploitation in the next 30 days, 92th percentile
Published
2011-12-14
Updated
2024-08-07

ExploitDB entries (3)

References

Related