CVE-2023-38886

HIGH7.2EPSS 50.4%

Dolibarr allows a remote privileged attacker to execute arbitrary code via a crafted command/script

Published: 9/20/2023Modified: 4/3/2025
Also known as:GHSA-6773-rfjv-c54wBIT-dolibarr-2023-38886

Description

An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (4)