CVE-2019-25450 HIGH

CVE-2019-25450: Dolibarr ERP/CRM 10.0.1 SQL Injection via card.php

Vendor Dolibarr
Product Dolibarr ERP/CRM
Weakness CWE-89 · SQLi
Published February 22, 2026
Last update April 7, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.

Key dates

02Disclosure timeline

February 22, 2026 CVE published
April 7, 2026 Record updated