Arbitrary Code Execution Vulnerability in Dolibarr ERP CRM by Dolibarr
CVE-2024-29477

8.8HIGH

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
3 April 2024

What is CVE-2024-29477?

A security vulnerability exists in Dolibarr ERP CRM due to insufficient input sanitization during the installation process. This weakness allows an attacker with adjacent network access to execute arbitrary code through specially crafted inputs. Effective remediation is essential to mitigate potential exploitation risks associated with this flaw.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.