CVE-2021-33816 Information
Jun 07, 2022
cve
Description
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system exec and shell_exec are blocked but backticks are not blocked.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://trovent.io/security-advisory-2106-01 https://trovent.github.io/security-advisories/TRSA-2106-01/TRSA-2106-01.txt http://seclists.org/fulldisclosure/2021/Nov/39
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: