Description
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Relevanssi-A Better Search 'Seach Query' Field HTML Injection (2.7.2)
WordPress Plugin Dropdown Menu Widget Cross-Site Request Forgery (1.9.1)
Contao Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1297)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-4753)