Description
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.7.x Cross-Site Scripting (1.7.0 - 1.7.2)
MongoDb Integer Overflow or Wraparound Vulnerability (CVE-2019-2392)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-35626)
WordPress Plugin Thank You Counter Button Multiple Cross-Site Scripting Vulnerabilities (1.8.7)
WordPress Plugin Asset Manager 'upload.php' Arbitrary File Upload (0.3)