UBUNTU-CVE-2020-13240

Source
https://ubuntu.com/security/CVE-2020-13240
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-13240.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-13240
Related
Published
2020-05-20T15:15:00Z
Modified
2024-10-15T14:07:29Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

References

Affected packages

Ubuntu:Pro:16.04:LTS / dolibarr

Package

Name
dolibarr
Purl
pkg:deb/ubuntu/dolibarr?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.5.5+dfsg1-2
3.5.7+dfsg1-1
3.5.8+dfsg1-1
3.5.8+dfsg1-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}