Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
References
| Link | Resource |
|---|---|
| https://sourceforge.net/projects/dolibarr/files/Dolibarr%20ERP-CRM/8.0.4/dolibarr-8.0.4.zip | Product |
| https://www.dolibarr.org/ | Product |
| https://www.exploit-db.com/exploits/46095 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/dolibarr-erp-crm-sql-injection-via-rowid-parameter | Third Party Advisory |
Configurations
History
17 Apr 2026, 14:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Dolibarr
Dolibarr dolibarr Erp\/crm |
|
| CPE | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | |
| References | () https://sourceforge.net/projects/dolibarr/files/Dolibarr%20ERP-CRM/8.0.4/dolibarr-8.0.4.zip - Product | |
| References | () https://www.dolibarr.org/ - Product | |
| References | () https://www.exploit-db.com/exploits/46095 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/dolibarr-erp-crm-sql-injection-via-rowid-parameter - Third Party Advisory |
12 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-12 13:16
Updated : 2026-04-17 14:25
NVD link : CVE-2019-25710
Mitre link : CVE-2019-25710
CVE.ORG link : CVE-2019-25710
JSON object : View
Products Affected
dolibarr
- dolibarr_erp\/crm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
