First published: Tue Jun 13 2023(Updated: )
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr ERP & CRM | >=16.0.0<16.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33568 is an issue in Dolibarr 16 before 16.0.5 that allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
An attacker can exploit CVE-2023-33568 by performing a database dump and accessing a company's customer file, prospects, suppliers, and employee information.
The severity of CVE-2023-33568 is high with a CVSS score of 7.5.
Versions of Dolibarr 16 before 16.0.5 are affected by CVE-2023-33568.
To fix CVE-2023-33568, upgrade Dolibarr to version 16.0.5 or above.