cve/2023/CVE-2023-38888.md
2024-06-09 00:33:16 +00:00

890 B

CVE-2023-38888

Description

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

POC

Reference

Github

No PoCs found on GitHub currently.