Dolibarr ERP-CRM SQL Injection Vulnerability in admin dict.php Endpoint

Vulnerability

A SQL injection vulnerability has been identified in Dolibarr ERP-CRM version 8.0.4. The issue resides in the 'rowid' parameter of the admin 'dict.php' endpoint, allowing attackers to execute arbitrary SQL queries. By injecting malicious SQL code through the 'rowid' POST parameter, attackers can exploit error-based SQL injection techniques to extract sensitive information from the database.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, potentially leading to unauthorized data access or manipulation.

Reproduction

To reproduce this vulnerability, send a POST request to the 'admin/dict.php' endpoint with the 'rowid' parameter injected with malicious SQL code. The injection can be crafted to exploit error-based SQL injection techniques, such as using the 'EXTRACTVALUE' function to extract database information.

Added: Apr 12, 2026, 1:21 PM
Updated: Apr 12, 2026, 1:21 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
3.1
exploitability
9.5
remediation
0.0
relevance
5.7
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.