Описание
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Ссылки
- Patch
- Patch
- MitigationVendor Advisory
- MitigationVendor Advisory
- ExploitThird Party Advisory
- Patch
- Patch
- MitigationVendor Advisory
- MitigationVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 16.0.0 (включая) до 16.0.5 (исключая)
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.8984
Высокий
7.5 High
CVSS3
Дефекты
CWE-552
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 2 лет назад
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
CVSS3: 7.5
debian
больше 2 лет назад
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers ...
CVSS3: 7.5
github
больше 2 лет назад
Dolibarr vulnerable to unauthenticated database access
EPSS
Процентиль: 100%
0.8984
Высокий
7.5 High
CVSS3
Дефекты
CWE-552