Description
|
|
(#Several vulnerabilities were reported in Dolibarr:#- CVE-2017-17897: SQL injection in the "comm/multiprix.php" file triggerable via the "id" parameter#- CVE-2017-17898: information disclosure due to non-blocking request to "*.tpl.php" files#- CVE-2017-17899: SQL injection in the "adherents/subscription/info.php" file triggerable via the "rowid" parameter#- CVE-2017-17900: SQL injection in the "fourn/index.php" file triggerable via the "socid" parameter.##Updated, 26/12/2017:#The dolibarr packages provided by Debian Jessie 8 and Stretch 9 are vulnerable.)
|