Critical severity9.1NVD Advisory· Published May 24, 2024· Updated Jun 17, 2026
CVE-2024-5314
CVE-2024-5314
Description
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | <= 9.0.1 | — |
Affected products
4- Dolibarr/ERP CMSv5Range: 9.0.1
- ghsa-coords2 versions
<= 9.0.1+ 1 more
- (no CPE)range: <= 9.0.1
- (no CPE)range: >= 9.0.1, < 18.0.5
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-c3h9-q3jx-w7fcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-5314ghsaADVISORY
- www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-dolibarrs-erp-cmsnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.