Логотип exploitDog
bind:CVE-2019-11201
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-11201

Количество 4

Количество 4

ubuntu логотип

CVE-2019-11201

больше 6 лет назад

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2019-11201

больше 6 лет назад

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2019-11201

больше 6 лет назад

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides f ...

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-jwg3-v9xm-v6q9

больше 3 лет назад

Dolibarr ERP and CRM Code Injection

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-11201

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

CVSS3: 8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11201

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

CVSS3: 8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11201

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides f ...

CVSS3: 8
1%
Низкий
больше 6 лет назад
github логотип
GHSA-jwg3-v9xm-v6q9

Dolibarr ERP and CRM Code Injection

CVSS3: 8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу