CVE-2023-38886: Code Injection
Published Sep 20, 2023
·Updated
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<17.0.1
17.0.1
dolibarr Dolibarr Erp\/crm<=17.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/dolibarr/dolibarrto a version that resolves this vulnerability.Fixed in 17.0.1
Event History
Sep 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
03:30 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Dolibarr ERP CRM?
The vulnerability ID for this issue in Dolibarr ERP CRM is CVE-2023-38886.
2
What is the severity of CVE-2023-38886?
The severity of CVE-2023-38886 is high (7.2).
3
How does this vulnerability in Dolibarr ERP CRM allow an attacker to execute arbitrary code?
This vulnerability in Dolibarr ERP CRM allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
4
What is the affected version of Dolibarr ERP CRM?
The affected version of Dolibarr ERP CRM is v.17.0.1 and versions before that.
5
Is there a fix available for CVE-2023-38886?
Yes, a fix is available for CVE-2023-38886. It is recommended to update to version 17.0.2 or later.