Description
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
Remediation
References
Related Vulnerabilities
WordPress Plugin Glass Cross-Site Request Forgery (1.3.2)
PHP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2023-3823)
Oracle Database Server CVE-2006-5332 Vulnerability (CVE-2006-5332)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-1103)