First published: Fri Aug 21 2020(Updated: )
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <11.0.5 | 11.0.5 |
Dolibarr Dolibarr | <11.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14201 is a vulnerability in Dolibarr CRM that allows privilege escalation, enabling authenticated attackers to upload arbitrary files.
Remote attackers can exploit this vulnerability by changing "disabled" to "enabled" in the HTML source code of societe/document.php, allowing them to upload arbitrary files.
CVE-2020-14201 has a severity rating of 6.5, which is considered medium.
The affected software is Dolibarr CRM before version 11.0.5.
To fix CVE-2020-14201, upgrade your Dolibarr CRM to version 11.0.5 or later.