CVE-2020-14201: Medium severity dolibarr vulnerability
Published Aug 21, 2020
·Updated
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<11.0.5
11.0.5
dolibarr Dolibarr<11.0.5
Event History
Aug 21, 2020
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
Description
May 24, 2022
Advisory Published
05:26 PM
Frequently Asked Questions
1
What is CVE-2020-14201?
CVE-2020-14201 is a vulnerability in Dolibarr CRM that allows privilege escalation, enabling authenticated attackers to upload arbitrary files.
2
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability by changing "disabled" to "enabled" in the HTML source code of societe/document.php, allowing them to upload arbitrary files.
3
What is the severity rating of CVE-2020-14201?
CVE-2020-14201 has a severity rating of 6.5, which is considered medium.
4
What is the affected software?
The affected software is Dolibarr CRM before version 11.0.5.
5
How do I fix CVE-2020-14201?
To fix CVE-2020-14201, upgrade your Dolibarr CRM to version 11.0.5 or later.