Description Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter. Remediation References CVE-2017-7886 Related Vulnerabilities Grafana Authentication Bypass by Spoofing Vulnerability (CVE-2022-35957) WordPress Plugin Global Content Blocks PHP Code Execution and Information Disclosure Vulnerabilities (1.5.1) Atlassian Jira CVE-2020-36237 Vulnerability (CVE-2020-36237) MySQL CVE-2016-0596 Vulnerability (CVE-2016-0596) MySQL CVE-2018-3137 Vulnerability (CVE-2018-3137) Severity Critical Classification CVE-2017-7886 CWE-138 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities