Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-38888

Опубликовано: 20 сент. 2023
Источник: debian

Описание

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dolibarrremovedpackage

Связанные уязвимости

CVSS3: 9.6
ubuntu
больше 2 лет назад

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

CVSS3: 9.6
nvd
больше 2 лет назад

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

CVSS3: 9.6
github
больше 2 лет назад

Cross Site Scripting vulnerability in Dolibarr ERP CRM