CVE-2023-33568 is a critical vulnerability affecting Dolibarr versions prior to 16.0.5, allowing unauthenticated attackers to perform a full database dump. This flaw, rated 7.5 HIGH on CVSS, enables access to sensitive company data including customer, prospect, supplier, and employee information if a contact file exists. While not currently on the KEV catalog, exploit modules are publicly available in Metasploit and Nuclei, indicating a high potential for exploitation despite limited public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0, < 16.0.5CPE matchmatch criteria | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.