Description
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
Remediation
References
Related Vulnerabilities
WordPress Plugin dwnldr Cross-Site Scripting (1.0)
PrestaShop URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-5270)
WordPress Plugin Download Shortcode Arbitrary File Disclosure (0.1)
Envoy Proxy Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2021-39162)
Internet Information Services Other Vulnerability (CVE-1999-0737)