CVE-2014-3992
Publication date 11 July 2014
Last updated 24 July 2024
Ubuntu priority
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php.
Status
Package | Ubuntu Release | Status |
---|---|---|
dolibarr | ||
18.04 LTS bionic | Not in release | |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |