CVE-2020-13240

Source
https://cve.org/CVERecord?id=CVE-2020-13240
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13240.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13240
Aliases
Downstream
Published
2020-05-20T15:15:11.187Z
Modified
2026-08-07T15:11:37.692046Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

References

Affected packages

Git / github.com/dolibarr/dolibarr

Affected ranges

Type
GIT
Repo
https://github.com/dolibarr/dolibarr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "11.0.4"
        },
        {
            "last_affected": "11.0.4"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:dolibarr:dolibarr_erp\\/crm:11.0.4:*:*:*:*:*:*:*"
}

Affected versions

11.*
11.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13240.json"