CVE-2019-25450 | Dolibarr ERP CRM 10.0.1 HTTP POST Request card.php actioncode/demand_reason_id/availability_id sql injection (Exploit 47370 / EDB-47370)
A vulnerability has been found in Dolibarr ERP CRM 10.0.1 and classified as critical. The impacted element is an unknown function of the file card.php of the component HTTP POST Request Handler. Performing a manipulation of the argument actioncode/demand_reason_id/availability_id results in sql injection.
This vulnerability was named CVE-2019-25450. The attack may be initiated remotely. In addition, an exploit is available.