299,184
Total vulnerabilities in the database
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
| Software | From | Fixed in |
|---|---|---|
| dolibarr / dolibarr_erp/crm | 11.0.4 | 11.0.4.x |