CVE-2023-38888
20.09.2023, 01:15
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Vendor | Product | Version |
---|---|---|
dolibarr | dolibarr_erp\/crm | 𝑥 ≤ 17.0.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases