First published: Thu Nov 17 2022(Updated: )
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | <14.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43138 is a vulnerability in Dolibarr Open Source ERP & CRM for Business before v14.0.1 that allows attackers to escalate privileges via a crafted API.
CVE-2022-43138 has a severity rating of 9.8, which is considered critical.
CVE-2022-43138 affects Dolibarr Open Source ERP & CRM for Business versions up to but not including v14.0.1.
An attacker can exploit CVE-2022-43138 by using a crafted API request to escalate privileges.
Yes, upgrading Dolibarr Open Source ERP & CRM to version 14.0.1 or newer will fix CVE-2022-43138.