S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Sep 24, 2024

CVE-2024-5315 Scanner

CVE-2024-5315 scanner - SQL Injection vulnerability in Dolibarr ERP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5315
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ERP CMSby Dolibarr
9.0.1
dolibarrby dolibarr
9.0.1
Updated Aug 22, 2026View on NVD →
Detail

Dolibarr ERP is an open-source software suite used by small and medium enterprises for managing their business operations. It offers tools for finance, project management, and customer relationship management. The software is widely utilized by organizations to streamline their processes and improve efficiency. Security vulnerabilities in such systems can have significant impacts on business integrity. Regular security assessments are essential to protect user data.

The detected SQL Injection vulnerability in Dolibarr ERP allows remote attackers to manipulate SQL queries through the viewstatut parameter in the list.php file. This could enable attackers to access sensitive data stored in the database. Exploitation of this vulnerability could lead to unauthorized data disclosure. Timely detection and remediation are crucial to safeguard against potential attacks.

The vulnerability is located in the list.php endpoint, specifically through the viewstatut parameter. Attackers can send specially crafted SQL queries to exploit this weakness. If successful, the attacker may retrieve all data from the database. The application fails to properly sanitize input, making it susceptible to SQL injection attacks. This can lead to significant information disclosure risks.

If exploited, this vulnerability could allow attackers to gain unauthorized access to sensitive data stored in the database. This may include personal information, financial records, or other confidential data. The integrity and confidentiality of the system could be severely compromised. Furthermore, it may lead to reputational damage for organizations using Dolibarr ERP. Prompt action is necessary to mitigate these risks.

By becoming a member of the S4E platform, you gain access to advanced scanning tools that continuously monitor your digital assets for vulnerabilities. Our comprehensive reporting helps you understand risks and take proactive measures to secure your systems. Benefit from expert insights and tailored solutions designed to protect your organization from cyber threats. Join us to enhance your security posture and stay ahead of potential risks.

References:

Solution Advice
  • Validate and sanitize all user inputs in the application.
  • Implement prepared statements or parameterized queries to prevent SQL injection.
  • Regularly update Dolibarr ERP to the latest secure version.
  • Conduct regular security assessments to identify and remediate vulnerabilities.
  • Educate staff on best practices for security and data protection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-5315 scanner - SQL Injection vulnerability in Dolibarr ERP S4E