First published: Wed May 06 2020(Updated: )
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr | <11.0.4 | |
composer/dolibarr/dolibarr | <12.0.0 | 12.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dolibarr vulnerability is CVE-2020-12669.
CVE-2020-12669 has a severity rating of 8.8 (high).
Dolibarr before version 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter in the core/get_menudiv.php script.
The affected software for CVE-2020-12669 is Dolibarr ERP/CRM versions up to and excluding 11.0.4.
To fix the Dolibarr vulnerability CVE-2020-12669, it is recommended to upgrade to version 11.0.4 or later.