SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categorieslist.php, /accountancy/admin/journalslist.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "11.1.1.9.0"
},
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:data_integrator",
"cpes": [
"cpe:2.3:a:oracle:data_integrator:11.1.1.9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
]
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.0.2"
}
],
"cpe": "cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*",
"source": [
"CPE_FIELD",
"REFERENCES"
]
}