PT-2019-12179 · Dolibarr · Dolibarr Erp/Crm

Priyank Nigam

·

Publicado

2019-07-29

·

Atualizado

2022-05-24

·

CVE-2019-11201

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dolibarr ERP/CRM version 9.0.1
Description The issue concerns the website module in Dolibarr ERP/CRM, which includes a WYSIWYG editor for creating public websites. This editor allows the inclusion of dynamic code, potentially leading to code execution on the host machine. An attacker, who must be a lower-privileged user of the application, can exploit this by checking a specific setting on the same page that enables the inclusion of dynamic content. As a result, code can be executed under the context and permissions of the underlying web server.
Recommendations For Dolibarr ERP/CRM version 9.0.1, consider disabling the WYSIWYG editor in the website module until a patch is available to prevent the inclusion of dynamic code and potential code execution. Restrict access to the website module to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11201
GHSA-JWG3-V9XM-V6Q9

Produtos afetados

Dolibarr Erp/Crm