PT-2023-26666 · Unknown · Dolibarr Erp/Crm

Published

2023-09-19

·

Updated

2025-04-03

·

CVE-2023-38886

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP CRM versions prior to 17.0.1
Description The issue allows a remote privileged attacker to execute arbitrary code via a crafted command or script. This enables the attacker to potentially gain control over the system, leading to unauthorized access and data manipulation.
Recommendations For versions prior to 17.0.1, update to a version that includes the fix for this issue to prevent arbitrary code execution. As a temporary workaround, consider restricting access to sensitive commands and scripts to minimize the risk of exploitation.

Exploit

Fix

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2023-38886
CVE-2023-38886
GHSA-6773-RFJV-C54W

Affected Products

Dolibarr Erp/Crm