9.6
CVSSv3

CVE-2023-38888

Published: 20/09/2023 Updated: 22/09/2023
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote malicious user to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr erp\\/crm