First published: Sun Jun 25 2017(Updated: )
Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <=5.0.3 | |
Dolibarr | <=5.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9840 is considered a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2017-9840, upgrade Dolibarr ERP/CRM to version 5.0.4 or later which addresses this vulnerability.
CVE-2017-9840 affects low-privilege users of Dolibarr ERP/CRM versions 5.0.3 and earlier.
Attackers can exploit CVE-2017-9840 to upload dangerous files, leading to arbitrary code execution within the application.
CVE-2017-9840 is a local vulnerability that requires authenticated access to the Dolibarr application.