ZeroHour

CVE-2020-13240

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

Vendors
dolibarr
Products
dolibarr erp\/crm
Weakness
CWE-276, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.