RULE(RULE ID:338008)

Rule General Information
Release Date: 2024-05-11
Rule Name: Dolibarr ERP and CRM Database Backup Command Injection Vulnerability (CVE-2023-38886)
Severity:
CVE ID:
Rule Protection Details
Description: An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://dolibarr.com
https://akerva.com/wp-content/uploads/2023/09/AKERVA_Security-Advisory_CVE-2023-38886_Dolibarr_RCE-1.pdf
Solutions
Refer to the announcement or patch by the vendor: http://dolibarr.com