An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
| Software | From | Fixed in |
|---|---|---|
dolibarr / dolibarr
|
- | 19.0.2 |
| dolibarr / dolibarr_erp/crm | - | 19.0.2 |