CVE-2020-12669: Input Validation
Published May 6, 2020
·Updated
core/getmenudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<12.0.0
12.0.0
dolibarr Dolibarr<11.0.4
Remediation
Event History
May 6, 2020
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:17 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Dolibarr vulnerability?
The vulnerability ID for this Dolibarr vulnerability is CVE-2020-12669.
2
What is the severity of CVE-2020-12669?
CVE-2020-12669 has a severity rating of 8.8 (high).
3
How does Dolibarr before version 11.0.4 allow remote attackers to bypass access restrictions?
Dolibarr before version 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter in the core/get_menudiv.php script.
4
What is the affected software for CVE-2020-12669?
The affected software for CVE-2020-12669 is Dolibarr ERP/CRM versions up to and excluding 11.0.4.
5
How can I fix the Dolibarr vulnerability CVE-2020-12669?
To fix the Dolibarr vulnerability CVE-2020-12669, it is recommended to upgrade to version 11.0.4 or later.