Dolibarr ERP/CRM是法国Dolibarr基金会的一套基于Web的企业资源计划(ERP)和客户关系管理(CRM)系统。该系统可用来管理产品、库存、发票、订单等。 Dolibarr ERP/CRM 9.0.1版本存在SQL注入漏洞。攻击者利用该漏洞向系统发送特制的 SQL 查询,并通过 /dolibarr/commande/list.php 中的参数 viewstatut 检索数据库中存储的所有信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5315.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet