CVE-2019-25450

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.1:*:*:*:*:*:*:*

History

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 7.5

25 Feb 2026, 18:31

Type Values Removed Values Added
CPE cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.1:*:*:*:*:*:*:*
References () https://www.exploit-db.com/exploits/47370 - () https://www.exploit-db.com/exploits/47370 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/dolibarr-erpcrm-sql-injection-via-cardphp - () https://www.vulncheck.com/advisories/dolibarr-erpcrm-sql-injection-via-cardphp - Broken Link
First Time Dolibarr
Dolibarr dolibarr Erp\/crm

23 Feb 2026, 18:13

Type Values Removed Values Added
Summary
  • (es) Dolibarr ERP/CRM 10.0.1 contiene múltiples vulnerabilidades de inyección SQL que permiten a atacantes autenticados manipular consultas de bases de datos inyectando código SQL a través de parámetros POST. Los atacantes pueden inyectar SQL malicioso a través de parámetros como actioncode, demand_reason_id y availability_id en los endpoints de card.php para extraer información sensible de la base de datos utilizando técnicas ciegas basadas en booleanos, basadas en errores y ciegas basadas en tiempo.

22 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-22 14:16

Updated : 2026-03-02 15:16


NVD link : CVE-2019-25450

Mitre link : CVE-2019-25450

CVE.ORG link : CVE-2019-25450


JSON object : View

Products Affected

dolibarr

  • dolibarr_erp\/crm
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')