Arbitrary Code Execution Vulnerability in Dolibarr ERP CRM by Dolibarr
CVE-2024-29477
8.8HIGH
What is CVE-2024-29477?
A security vulnerability exists in Dolibarr ERP CRM due to insufficient input sanitization during the installation process. This weakness allows an attacker with adjacent network access to execute arbitrary code through specially crafted inputs. Effective remediation is essential to mitigate potential exploitation risks associated with this flaw.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
