Описание
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:11.0.4:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00169
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-276
Связанные уязвимости
CVSS3: 5.4
ubuntu
больше 5 лет назад
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
CVSS3: 5.4
debian
больше 5 лет назад
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup doc ...
EPSS
Процентиль: 38%
0.00169
Низкий
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-276