CVE-2023-38888

CRITICAL9.6EPSS 5.0%

Cross Site Scripting vulnerability in Dolibarr ERP CRM

Published: 9/20/2023Modified: 4/3/2025
Also known as:GHSA-62wf-h26v-5m57BIT-dolibarr-2023-38888

Description

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

References (4)