PT-2020-2779 · Dolibarr · Dolibarr

Published

2020-05-06

·

Updated

2022-05-24

·

CVE-2020-12669

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dolibarr versions prior to 11.0.4
Description The issue is related to the core/get menudiv.php component in Dolibarr, which lacks proper input validation. This allows remote authenticated attackers to bypass intended access restrictions by providing a non-alphanumeric menu parameter, potentially leading to unauthorized access to protected information.
Recommendations For versions prior to 11.0.4, update to version 11.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the core/get menudiv.php component until a patch is applied. Avoid using non-alphanumeric characters in the menu parameter to minimize the risk of exploitation.

Fix

Incorrect Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02874
CVE-2020-12669
GHSA-RG8M-84JF-9367

Affected Products

Dolibarr