Description
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
Remediation
References
Related Vulnerabilities
UAParser.js Inefficient Regular Expression Complexity Vulnerability (CVE-2022-25927)
MySQL CVE-2017-3450 Vulnerability (CVE-2017-3450)
WordPress Improper Input Validation Vulnerability (CVE-2020-35539)
PHP Other Vulnerability (CVE-2015-8876)
WordPress Plugin Dynamic Widgets 'id' Parameter Cross-Site Scripting (1.5.1)