Description
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Donorbox-Free Recurring Donation Form Cross-Site Scripting (7.1.1)
WordPress Plugin NextGEN Gallery-WordPress Gallery Unspecified Vulnerability (2.0.77.3)
SharePoint CVE-2021-40486 Vulnerability (CVE-2021-40486)
PHP Insufficient Verification of Data Authenticity Vulnerability (CVE-2024-5458)
phpMyAdmin Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-1000017)