Description
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
Remediation
References
Related Vulnerabilities
Family Connections Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-0699)
WordPress Plugin Affiliate Power-Sales Tracking for Affiliate Marketers Cross-Site Scripting (2.2.0)
Oracle Application Server Other Vulnerability (CVE-2006-0552)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5625)