---
id: CVE-2019-25710
title: >-
  Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid
  parameter of the admin dict.php endpoint that allows attackers to execute
  arbitrary SQL queries
summary: >-
  Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid
  parameter of the admin dict.php endpoint that allows attackers to execute
  arbitrary SQL queries. Attackers can inject malicious SQL code through the
  rowid POST p…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
vendor: dolibarr
product: dolibarr_erp/crm
affected:
  - dolibarr_erp/crm <= 8.0.4
published: '2026-04-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:43.260'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25710'
references:
  - url: >-
      https://sourceforge.net/projects/dolibarr/files/Dolibarr%20ERP-CRM/8.0.4/dolibarr-8.0.4.zip
    label: disclosure@vulncheck.com
  - url: 'https://www.dolibarr.org/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46095'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dolibarr-erp-crm-sql-injection-via-rowid-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-13T12:07:10.291007Z'
epss: 0.00311
epssPercentile: 0.2197
ingestedAt: '2026-10-08T16:52:14.677Z'
---

## Overview

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

## Affected

- `dolibarr_erp/crm <= 8.0.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
