The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-3722 | The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS. |
![]() |
GHSA-f848-r5g6-6gpf | Dolibarr Stored Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.dubget.com/stored-xss-via-file-upload.html |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:11:19.412Z
Reserved: 2020-05-20T00:00:00
Link: CVE-2020-13240

No data.

Status : Modified
Published: 2020-05-20T15:15:11.187
Modified: 2024-11-21T05:00:51.663
Link: CVE-2020-13240

No data.

No data.