CVE-2020-13240: XSS
Published May 20, 2020
·Updated
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Affected Software
2 affected components
composer/dolibarr/dolibarr=11.0.4
dolibarr Dolibarr Erp\/crm=11.0.4
Event History
May 20, 2020
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:18 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13240.
2
What is the severity of CVE-2020-13240?
CVE-2020-13240 has a severity keyword of medium and a severity value of 5.4.
3
What does the DMS/ECM module vulnerability in Dolibarr 11.0.4 allow?
The vulnerability allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions, bypassing the .noexe protection mechanism against XSS.
4
What software version is affected by CVE-2020-13240?
Dolibarr 11.0.4 is affected by CVE-2020-13240.
5
How can the vulnerability in Dolibarr 11.0.4 be fixed?
To fix the vulnerability, it is recommended to update Dolibarr to the latest version available.