CVE-2017-9840: Malicious File Upload
Published Jun 25, 2017
·Updated
Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.
Affected Software
2 affected components
composer/dolibarr/dolibarr<=5.0.3
dolibarr Dolibarr<=5.0.3
Event History
Jun 25, 2017
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
May 17, 2022
Advisory Published
02:39 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-9840?
CVE-2017-9840 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2017-9840?
To fix CVE-2017-9840, upgrade Dolibarr ERP/CRM to version 5.0.4 or later which addresses this vulnerability.
3
Who is affected by CVE-2017-9840?
CVE-2017-9840 affects low-privilege users of Dolibarr ERP/CRM versions 5.0.3 and earlier.
4
What can attackers do with CVE-2017-9840?
Attackers can exploit CVE-2017-9840 to upload dangerous files, leading to arbitrary code execution within the application.
5
Is CVE-2017-9840 a local or remote vulnerability?
CVE-2017-9840 is a local vulnerability that requires authenticated access to the Dolibarr application.