Dolibarr ERP CRM 16.0.3

CPE Details

Dolibarr ERP CRM 16.0.3
16.0.3
2023-06-23
13h57 +00:00
2023-07-14
11h42 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:dolibarr:dolibarr_erp\/crm:16.0.3:*:*:*:*:*:*:*

Informations

Vendor

dolibarr

Product

dolibarr_erp\/crm

Version

16.0.3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-3991 2024-11-15 10h52 +00:00 An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
4.3
Moyen
CVE-2023-4198 2023-11-01 08h01 +00:00 Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
6.5
Moyen
CVE-2023-4197 2023-11-01 07h58 +00:00 Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
8.8
Haute
CVE-2023-5842 2023-10-30 00h00 +00:00 Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
4.8
Moyen
CVE-2023-5323 2023-10-01 00h00 +00:00 Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
6.1
Moyen
CVE-2023-38886 2023-09-19 22h00 +00:00 An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
7.2
Haute
CVE-2023-38887 2023-09-19 22h00 +00:00 File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
8.8
Haute
CVE-2023-38888 2023-09-19 22h00 +00:00 Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
9.6
Critique
CVE-2023-33568 2023-06-12 22h00 +00:00 An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
7.5
Haute
CVE-2023-30253 2023-05-28 22h00 +00:00 Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation:
8.8
Haute