Vulnerabilities > Dolibarr > Dolibarr ERP CRM > 17.0.3

DATE CVE VULNERABILITY TITLE RISK
2024-11-15 CVE-2021-3991 Authorization Bypass Through User-Controlled Key vulnerability in Dolibarr Erp/Crm
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch.
network
low complexity
dolibarr CWE-639
4.3
2024-04-03 CVE-2024-29477 Code Injection vulnerability in Dolibarr Erp/Crm
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.
low complexity
dolibarr CWE-94
8.8
2023-11-01 CVE-2023-4198 Missing Authorization vulnerability in Dolibarr Erp/Crm
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
network
low complexity
dolibarr CWE-862
6.5
2023-11-01 CVE-2023-4197 Injection vulnerability in Dolibarr Erp/Crm
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
network
low complexity
dolibarr CWE-74
8.8
2023-10-01 CVE-2023-5323 Unspecified vulnerability in Dolibarr Erp/Crm
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
network
low complexity
dolibarr
6.1