Description
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
Remediation
References
Related Vulnerabilities
WordPress Plugin Duplicator-WordPress Migration Cross-Site Scripting (0.5.26)
WordPress Plugin vSlider Multi Image Slider for WordPress Arbitrary File Upload (4.1.2)
WordPress Plugin Ad Inserter-Ad Manager & AdSense Ads Unspecified Vulnerability (2.6.21)
qdPM Code Execution Vulnerability (CVE-2015-3884)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0346)