First published: Wed Sep 20 2023(Updated: )
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | <=17.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dolibarr ERP CRM vulnerability is CVE-2023-38888.
The severity of CVE-2023-38888 is critical with a CVSS score of 9.6.
The Dolibarr ERP CRM vulnerability CVE-2023-38888 is a Cross-Site Scripting (XSS) vulnerability that allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module.
Dolibarr ERP CRM v.17.0.1 and earlier versions are affected by CVE-2023-38888.
To fix the Dolibarr ERP CRM vulnerability CVE-2023-38888, update to version 17.0.1 or later.