PT-2023-26666 · Unknown · Dolibarr Erp/Crm
Publicado
2023-09-19
·
Atualizado
2025-04-03
·
CVE-2023-38886
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dolibarr ERP CRM versions prior to 17.0.1
Description
The issue allows a remote privileged attacker to execute arbitrary code via a crafted command or script. This enables the attacker to potentially gain control over the system, leading to unauthorized access and data manipulation.
Recommendations
For versions prior to 17.0.1, update to a version that includes the fix for this issue to prevent arbitrary code execution.
As a temporary workaround, consider restricting access to sensitive commands and scripts to minimize the risk of exploitation.
Exploit
Correção
Code Injection
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dolibarr Erp/Crm