2023-06-15 16:00:37 +00:00

36 lines
1.2 KiB
JSON

{
"id": "CVE-2023-33568",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-06-13T15:15:14.147",
"lastModified": "2023-06-15T14:15:09.630",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/Dolibarr/dolibarr/commit/bb7b69ef43673ed403436eac05e0bc31d5033ff7",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/Dolibarr/dolibarr/commit/be82f51f68d738cce205f4ce5b469ef42ed82d9e",
"source": "cve@mitre.org"
},
{
"url": "https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471",
"source": "cve@mitre.org"
},
{
"url": "https://www.dolibarr.org/forum/t/dolibarr-16-0-security-breach/23471/1",
"source": "cve@mitre.org"
},
{
"url": "https://www.dsecbypass.com/en/dolibarr-pre-auth-contact-database-dump/",
"source": "cve@mitre.org"
}
]
}