CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.6. It may be remotely exploitable.
CVE
CVE-2023-38888
Severity
CRITICAL
CVSS
9.6
EPSS
1.11%
Original NVD Description
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Related CVEs
Other vulnerabilities affecting the same vendor(s)