Insecure file upload In dolibarr/dolibarr
Description
Dolibarr arbitrary file upload vulnerability An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 19.0.2 |
Aliases
1. 2. 3. 4.
References
1. 2.