module

Dolibarr 16 pre-auth contact database dump

Disclosed
Mar 14, 2023
Created
May 30, 2023

Description

Dolibarr version 16 An unauthenticated attacker may retrieve a company's entire customer file, prospects, suppliers,
and potentially employee information if a contact file exists.
Both public and private notes are also included in the dump.

Authors

Vladimir TOUTAIN
Nolan LOSSIGNOL-DRILLIEN

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/scanner/http/dolibarr_16_contact_dump
msf auxiliary(dolibarr_16_contact_dump) > show actions
...actions...
msf auxiliary(dolibarr_16_contact_dump) > set ACTION < action-name >
msf auxiliary(dolibarr_16_contact_dump) > show options
...show and set options...
msf auxiliary(dolibarr_16_contact_dump) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.