CVE-2024-37821: Dolibarr Erp/crm

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.

Affected products

  • Dolibarr Dolibarr Erp/crm: before 19.0.2 (fixed in 19.0.2)

Published 2024-06-18. Last modified 2026-07-09.