CVE-2023-33568
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2023
Last modified:
23/06/2023
Description
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.0.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/Dolibarr/dolibarr/commit/bb7b69ef43673ed403436eac05e0bc31d5033ff7
- https://github.com/Dolibarr/dolibarr/commit/be82f51f68d738cce205f4ce5b469ef42ed82d9e
- https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471
- https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471/1
- https://www.dsecbypass.com/en/dolibarr-pre-auth-contact-database-dump/



