PT-2023-26666 · Unknown · Dolibarr Erp/Crm

Publicado

2023-09-19

·

Atualizado

2025-04-03

·

CVE-2023-38886

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP CRM versions prior to 17.0.1
Description The issue allows a remote privileged attacker to execute arbitrary code via a crafted command or script. This enables the attacker to potentially gain control over the system, leading to unauthorized access and data manipulation.
Recommendations For versions prior to 17.0.1, update to a version that includes the fix for this issue to prevent arbitrary code execution. As a temporary workaround, consider restricting access to sensitive commands and scripts to minimize the risk of exploitation.

Exploit

Correção

Code Injection

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DOLIBARR-2023-38886
CVE-2023-38886
GHSA-6773-RFJV-C54W

Produtos afetados

Dolibarr Erp/Crm