HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2019-25710 — Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid para...

·Source: NIST NVD

Updated:

Executive Summary

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

Analysis

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques. CVSS Score: 8.2. Published: 2026-04-12T13:16:34.127.

Indicators of Compromise (1)

CVE (1)
CVE-2019-25710
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats