EXPOSURES › CVE-2023-38888
CVE-2023-38888
CRITICAL
DETAIL
SourceNVD · cve
Published2023-09-20
CVSS9.6
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-38888 ↗
⚡ RCE
SHAME 50/100
rce
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.