Описание
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:6.0.4:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00258
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 8 лет назад
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
CVSS3: 7.5
debian
около 8 лет назад
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl ...
EPSS
Процентиль: 49%
0.00258
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200