CVE-2019-25452Disclosure(dolibarr / dolibarr_erp\/crm)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract sensitive database information using error-based or time-based blind SQL injection techniques.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dolibarr_erp\/crm

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-22); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
dolibarr_erp\/crm

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-22: 1Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-03-23: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-23: 102-2202-2402-2703-23
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-221
Disclosure1
2026-02-241
Disclosure1
2026-02-271
Disclosure1
2026-03-231
General1
Full discourse4 posts
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. 💉 CVE-2019-25455 (CVSS: 7.5) 2. 💉 CVE-2019-25452 (CVSS: 7.5) 3. 💉 CVE-2019-25450 (CVSS: 7.5) 4. 💉 CVE-2019-25446 (CVSS: 8.2) 5. 💉 CVE-2019-25443 (CVSS: 8.2) #CyberSecurity #CVE #Infosec

    Post summary

    The post lists several recent CVEs with their CVSS scores but provides no detail on exploitation, patches, or proof of concept, presenting a general vulnerability bulletin.

    0000015
    167 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2019-25452 (CVSS:8.8, HIGH) is Analyzed. Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint..https://nvd.nist.gov/vuln/detail/CVE-2019-25452 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post discloses an SQL injection vulnerability in Dolibarr ERP/CRM 10.0.1, providing the affected parameter and CVSS score, but offers no PoC, exploit, or patch information.

    0000016
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An #SQLi vulnerability (UBUNTU-CVE-2019-25452) in `Dolibarr ERP/CRM` 10.0.1 allows unauthenticated attackers to execute arbitrary SQL queries. Review your `Dolibarr` installations. #infosec #Dolibarr https://www.pulsepatch.io/posts/ubuntu-cve-2019-25452-dolibarr-sql-injection

    Post summary

    The post announces a SQL injection vulnerability (UBUNTU-CVE-2019-25452) in Dolibarr ERP/CRM 10.0.1 that permits unauthenticated attackers to run arbitrary SQL queries, urging users to review their installations.

    0000058
    1 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2019-25452** pertains to an SQL injection vulnerability found in Dolibarr ERP/CRM version 10.0.1. Specifically, the flaw resides in the `viewcat.php` endpoint, where the `elemid` POST parameter is improperly sanitized, allowing attackers to inject malicious SQL code. This vulnerability can be exploited without authentication, making it particularly dangerous. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #SQLInjection #PrivilegeEscalation https://cvetodo.com/cve/CVE-2019-25452

    Post summary

    The post discloses an unauthenticated SQL injection flaw in Dolibarr 10.0.1’s viewcat.php, allowing attackers to inject malicious SQL via the elemid POST parameter.

    0000037
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdolibarrdolibarr_erp\/crm10.0.1--

Explore more