Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Arthur Valverde M

#16464of 53,638
16.3Total CVSS
Vulnerabilities · 2
High
2
PT-2024-27767
8.8
2024-06-18
Unknown · Dolibarr Erp/Crm · CVE-2024-37821
**Name of the Vulnerable Software and Affected Versions** Dolibarr ERP CRM versions up to 19.0.1 **Description** The issue concerns an arbitrary file upload vulnerability in the Upload Template function. This vulnerability allows attackers to execute arbitrary code by uploading a crafted .SQL file. **Recommendations** For versions up to 19.0.1, consider disabling the Upload Template function until a patch is available to prevent exploitation. Restrict access to the Upload Template feature to minimize the risk of arbitrary code execution.
PT-2024-24124
7.5
2024-04-16
Unknown · Dolibarr Erp/Crm · CVE-2024-31503
**Name of the Vulnerable Software and Affected Versions** Dolibarr ERP CRM versions 19.0.0 and before **Description** The issue allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover. This occurs due to incorrect access control in the software. **Recommendations** For versions 19.0.0 and before, update to a version that includes the necessary access control fixes to prevent session cookie and CSRF token theft. As a temporary workaround, consider restricting user interaction with crafted web pages to minimize the risk of exploitation.