{"id":"BIT-dolibarr-2024-29477","details":"Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.","aliases":["CVE-2024-29477","GHSA-p73x-rpgm-3v56"],"modified":"2025-04-03T15:26:59.514226Z","published":"2025-04-03T14:07:04.092Z","database_specific":{"cpes":["cpe:2.3:a:dolibarr:dolibarr_erp/crm:*:*:*:*:*:*:*:*"],"severity":"High"},"references":[{"type":"WEB","url":"http://dolibarr.com"},{"type":"WEB","url":"https://github.com/alexbsec/CVEs/blob/master/2024/CVE-2024-29477.md"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29477"}],"affected":[{"package":{"name":"dolibarr","ecosystem":"Bitnami","purl":"pkg:bitnami/dolibarr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"19.0.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/dolibarr/BIT-dolibarr-2024-29477.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.7.3"}