Vulnerability Description
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | <= 17.0.3 |
Related Weaknesses (CWE)
References
- https://github.com/Dolibarr/dolibarr/commit/3065b9ca6ade988e8d7a8a8550415c0abb56Patch
- https://starlabs.sg/advisories/23/23-4198ExploitThird Party Advisory
- https://github.com/Dolibarr/dolibarr/commit/3065b9ca6ade988e8d7a8a8550415c0abb56Patch
- https://starlabs.sg/advisories/23/23-4198ExploitThird Party Advisory
FAQ
What is CVE-2023-4198?
CVE-2023-4198 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
How severe is CVE-2023-4198?
CVE-2023-4198 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4198?
Check the references section above for vendor advisories and patch information. Affected products include: Dolibarr Dolibarr Erp\/Crm.