CVE-2012-1225: Dolibarr Erp/crm
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.
Affected products
- Dolibarr Dolibarr Erp/crm: up to and including 3.2.0; version 2.5.0 only; version 2.6.0 only; version 2.6.1 only; version 2.7.0 only; version 2.7.1 only; …
Published 2012-02-21. Last modified 2026-06-16.