An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
2024-06-18T20:15:13.640
2025-06-13T16:17:59.667
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dolibarr | dolibarr_erp\/crm | < 19.0.2 | Yes |