Описание
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
Ссылки
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:3.3.1:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.0381
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 6 лет назад
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
CVSS3: 9.8
debian
около 6 лет назад
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewim ...
CVSS3: 9.8
github
почти 4 года назад
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
EPSS
Процентиль: 88%
0.0381
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-20