High severity8.0NVD Advisory· Published Jul 29, 2019· Updated Jun 17, 2026
CVE-2019-11201
CVE-2019-11201
Description
Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | < 9.0.3 | 9.0.3 |
Affected products
3- Dolibarr/ERP/CRMdescription
Patches
Vulnerability mechanics
References
5- know.bishopfox.com/advisories/dolibarr-version-9-0-1-vulnerabilitiesnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jwg3-v9xm-v6q9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-11201ghsaADVISORY
- github.com/Dolibarr/dolibarr/commit/63c0ab93fb21f86c1b736061af9fa1eee90148fdghsaWEB
- github.com/Dolibarr/dolibarr/issues/10984ghsaWEB
News mentions
0No linked articles in our index yet.