Description
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
Remediation
References
Related Vulnerabilities
WordPress Plugin Media Library Assistant Multiple Cross-Site Scripting Vulnerabilities (2.73)
WordPress Plugin Allow PHP in Posts and Pages 'id' Parameter SQL Injection (2.0.0.RC1)
MySQL CVE-2020-14793 Vulnerability (CVE-2020-14793)
WordPress Plugin FlightLog SQL Injection (3.0.2)
Joomla Improper Certificate Validation Vulnerability (CVE-2017-11364)