{ "id": "CVE-2023-33568", "sourceIdentifier": "cve@mitre.org", "published": "2023-06-13T15:15:14.147", "lastModified": "2023-06-15T14:15:09.630", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists." } ], "metrics": {}, "references": [ { "url": "https://github.com/Dolibarr/dolibarr/commit/bb7b69ef43673ed403436eac05e0bc31d5033ff7", "source": "cve@mitre.org" }, { "url": "https://github.com/Dolibarr/dolibarr/commit/be82f51f68d738cce205f4ce5b469ef42ed82d9e", "source": "cve@mitre.org" }, { "url": "https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471", "source": "cve@mitre.org" }, { "url": "https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471/1", "source": "cve@mitre.org" }, { "url": "https://www.dsecbypass.com/en/dolibarr-pre-auth-contact-database-dump/", "source": "cve@mitre.org" } ] }