CVE-2020-13239: XSS
Published May 20, 2020
·Updated
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
Affected Software
2 affected components
composer/dolibarr/dolibarr=11.0.4
dolibarr Dolibarr Erp\/crm=11.0.4
Event History
May 20, 2020
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:18 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13239.
2
What is the severity of CVE-2020-13239?
The severity of CVE-2020-13239 is medium (5.4).
3
What is the affected software version of CVE-2020-13239?
The affected software version of CVE-2020-13239 is Dolibarr 11.0.4.
4
How does CVE-2020-13239 impact Dolibarr?
CVE-2020-13239 allows user-uploaded .html files to be rendered in the browser, potentially leading to XSS attacks.
5
Is there a fix available for CVE-2020-13239?
No fix information is available.