Remote Code Execution Vulnerability in Dolibarr ERP CRM
CVE-2023-38886

7.2HIGH

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
20 September 2023

What is CVE-2023-38886?

Dolibarr ERP CRM versions 17.0.1 and prior have a vulnerability that allows remote attackers to execute arbitrary code on the server. By exploiting this flaw, an unauthorized user can craft special commands or scripts that, when executed, compromise the integrity and security of the application, potentially leading to unauthorized access and system exploitation.

References

EPSS Score

48% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.