Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.
{
"nvd_published_at": "2017-06-25T12:29:00Z",
"severity": "HIGH",
"github_reviewed_at": "2023-07-27T21:06:34Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-434"
]
}