Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p73x-rpgm-3v56

Опубликовано: 03 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Dolibarr ERP CRM Code Injection vulnerability during installation

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

<= 19.0.0

Отсутствует

EPSS

Процентиль: 35%
0.00143
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 2 года назад

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.

CVSS3: 8.8
nvd
почти 2 года назад

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.

CVSS3: 8.8
debian
почти 2 года назад

Lack of sanitization during Installation Process in Dolibarr ERP CRM u ...

EPSS

Процентиль: 35%
0.00143
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-94