CVE-2024-37821: Malicious File Upload
Published Jun 18, 2024
·Updated
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<19.0.2
19.0.2
dolibarr Dolibarr Erp\/crm<19.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/dolibarr/dolibarrto a version that resolves this vulnerability.Fixed in 19.0.2
Event History
Jun 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-37821?
The severity of CVE-2024-37821 is critical due to the potential for attackers to execute arbitrary code.
2
How do I fix CVE-2024-37821?
To fix CVE-2024-37821, upgrade Dolibarr ERP CRM to version 19.0.2 or later.
3
What systems are affected by CVE-2024-37821?
CVE-2024-37821 affects Dolibarr ERP CRM versions up to 19.0.1.
4
What type of vulnerability is CVE-2024-37821?
CVE-2024-37821 is an arbitrary file upload vulnerability in the Upload Template function.
5
Can CVE-2024-37821 be exploited remotely?
Yes, CVE-2024-37821 can be exploited remotely by uploading a crafted .SQL file.