vendor:
Dolibarr ERP & CRM
by:
Vulnerability-Lab researcher
9
CVSS
CRITICAL
File Include Vulnerabilities
98
CWE
Product Name: Dolibarr ERP & CRM
Affected Version From: 3.2.0 Alpha
Affected Version To: 3.2.0 Alpha
Patch Exists: YES
Related CWE: N/A
CPE: a:dolibarr:dolibarr:3.2.0_alpha
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web-based
2012
Dolibarr CMS v3.2.0 Alpha – File Include Vulnerabilities
Multiple File Include Vulnerabilities are detected on Dolibarrs Content Management System v3.2.0 Alpha. The vulnerability allows an attacker (remote) or local low privileged user account to request local web-server or system files. Successful exploitation of the vulnerability results in dbms & application compromise.
Mitigation:
Update to the latest version