CVE-2022-4093
CRITICAL9.8EPSS 0.32%SQL Injection in dolibarr/dolibarr
發布日:2022/11/21修改日:2025/5/20
描述
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected
受影響套件(2)
- Bitnami/dolibarr>= 16.0.1, <= 16.0.1, >= 16.0.2, <= 16.0.2
- Packagist/dolibarr/dolibarr>= 16.0.1, < 16.0.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |