CVE-2023-33568
HIGH NUCLEIDolibarr 16.0.0-16.0.4 - Unauthenticated Database Dump via Contact File Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-33568.
PoCs published by Vladimir TOUTAIN, Nolan LOSSIGNOL-DRILLIEN, including Metasploit module auxiliary/scanner/http/dolibarr_16_contact_dump.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated information disclosure vulnerability in Dolibarr 16.0.0-16.0.4, allowing attackers to dump the entire contact database including sensitive details via a crafted GET request to the public ticket endpoint.
Description
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Exploits (1)
This Metasploit module exploits an unauthenticated information disclosure vulnerability in Dolibarr 16.0.0-16.0.4, allowing attackers to dump the entire contact database including sensitive details via a crafted GET request to the public ticket endpoint.
Nuclei Templates (1)
http.favicon.hash:440258421
icon_hash=440258421
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N