The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.dubget.com/stored-xss-via-file-upload.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-20T14:57:22
Updated: 2024-08-04T12:11:19.412Z
Reserved: 2020-05-20T00:00:00
Link: CVE-2020-13240
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-20T15:15:11.187
Modified: 2024-11-21T05:00:51.663
Link: CVE-2020-13240
Redhat
No data.