Описание
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Release NotesThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
Связанные уязвимости
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
Dolibarr before 11.0.5 allows low-privilege users to upload files of d ...
Dolibarr Unrestricted Upload of File with Dangerous Type
EPSS
8.8 High
CVSS3
6.5 Medium
CVSS2