Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11201

Опубликовано: 29 июл. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 8.5
CVSS3: 8

Описание

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

РелизСтатусПримечание
bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

8.5 High

CVSS2

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
больше 6 лет назад

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

CVSS3: 8
debian
больше 6 лет назад

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides f ...

CVSS3: 8
github
больше 3 лет назад

Dolibarr ERP and CRM Code Injection

8.5 High

CVSS2

8 High

CVSS3