Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr
Dolibarr dolibarr Erp/crm |
|
| Vendors & Products |
Dolibarr
Dolibarr dolibarr Erp/crm |
Sun, 22 Feb 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques. | |
| Title | Dolibarr ERP/CRM 10.0.1 SQL Injection via card.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-22T13:18:24.715Z
Reserved: 2026-02-20T18:37:23.205Z
Link: CVE-2019-25450
No data.
Status : Awaiting Analysis
Published: 2026-02-22T14:16:01.990
Modified: 2026-02-23T18:13:53.397
Link: CVE-2019-25450
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:29:07Z