CVE-2019-25450 Details
Description
Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.
A series of SQL injection vulnerabilities have been identified in Dolibarr ERP/CRM version 10.0.1. These vulnerabilities allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. The affected parameters include actioncode, demand_reason_id, and availability_id, all within card.php endpoints. Exploitation of these vulnerabilities could lead to unauthorized access to sensitive database information using various SQL injection techniques, such as boolean-based blind, error-based, and time-based blind methods.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/47370 | [email protected] | ExploitVDB Entry |
| https://www.vulncheck.com/advisories/dolibarr-erpcrm-sql-injection-via-cardphp | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dolibarr dolibarr erp/crm | 10.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | CVE Modified | [email protected] |
| Feb 25, 2026 | Initial Analysis | [email protected] |
| Feb 22, 2026 | New CVE Received | [email protected] |