Description
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Media Tagz Gallery Multiple Unspecified Vulnerabilities (1.0)
Drupal Other Vulnerability (CVE-2006-1225)
SharePoint CVE-2023-21717 Vulnerability (CVE-2023-21717)
WordPress Plugin Widget for Facebook Page Feeds Cross-Site Scripting (5.0)
Joomla! Core 2.5.x Clickjacking Vulnerability (2.5.0 - 2.5.7)