GHSA-g8h7-mcp6-pf47
GitHub Security Advisory
File Upload vulnerability in Dolibarr ERP CRM
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Affected Packages
Packagist
dolibarr/dolibarr
Affected versions:
0
(fixed in 17.0.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.