PT-2020-13390 · Dolibarr · Dolibarr

Published

2020-05-20

·

Updated

2025-04-03

·

CVE-2020-13240

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr version 11.0.4
Description The issue allows users with the 'Setup documents directories' permission to rename uploaded files, giving them insecure file extensions. This bypasses the .noexe protection mechanism, potentially leading to XSS attacks.
Recommendations For Dolibarr version 11.0.4, consider restricting the 'Setup documents directories' permission to trusted users until a patch is available. As a temporary workaround, monitor file uploads and renaming activities closely to minimize the risk of exploitation.

Exploit

Fix

XSS

Exposure of Resource to Wrong Sphere

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2020-13240
CVE-2020-13240
GHSA-F848-R5G6-6GPF

Affected Products

Dolibarr