First published: Wed Sep 20 2023(Updated: )
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <17.0.1 | 17.0.1 |
Dolibarr ERP & CRM | <=17.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38887 is a file upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before that allows a remote attacker to execute arbitrary code and obtain sensitive information.
CVE-2023-38887 allows a remote attacker to exploit the extension filtering and renaming functions in Dolibarr ERP CRM, enabling them to upload and execute arbitrary code and obtain sensitive information.
The severity of CVE-2023-38887 is rated as high with a CVSS score of 8.8.
To fix CVE-2023-38887, it is recommended to update Dolibarr ERP CRM to version 17.0.1 or later, as this vulnerability has been patched in that release.
More information about CVE-2023-38887 can be found on the Dolibarr website, AKERVA Security Advisory, and NIST's vulnerability database.