Description
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP iCommerce-the first interactive ecommerce for wordpress SQL Injection (1.1.1)
Twisted Web HTTP Server Improper Certificate Validation Vulnerability (CVE-2014-7143)
WordPress Plugin WordPress Popular Posts Cross-Site Scripting (3.3.2)
Joomla Incorrect Authorization Vulnerability (CVE-2023-23751)