CVE-2017-9840

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
25/06/2017
Last modified:
20/04/2025

Description

Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:* 5.0.3 (including)