Description
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3839 | The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS. |
Github GHSA |
GHSA-fvf9-2hjp-w936 | Dolibarr Stored Cross-site Scripting via file upload |
References
| Link | Providers |
|---|---|
| https://www.dubget.com/stored-xss-via-file-upload.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:11:19.395Z
Reserved: 2020-05-20T00:00:00.000Z
Link: CVE-2020-13239
No data.
Status : Modified
Published: 2020-05-20T15:15:11.127
Modified: 2024-11-21T05:00:51.513
Link: CVE-2020-13239
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA