Description
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Relevanssi-A Better Search SQL Injection (3.6.0)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605)
WordPress Plugin Modern Events Calendar Lite Cross-Site Scripting (5.22.1)
WordPress Plugin Integration for Contact Form 7 and Infusionsoft Cross-Site Scripting (1.1.2)
Oracle Database Server CVE-2006-5332 Vulnerability (CVE-2006-5332)