Arbitrary File Upload Affecting dolibarr/dolibarr package, versions >=0.0.0
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.06% (26th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-DOLIBARRDOLIBARR-570054
- published 21 May 2020
- disclosed 21 May 2020
- credit Unknown
Introduced: 21 May 2020
CVE-2020-13240 Open this link in a new tabHow to fix?
There is no fixed version for dolibarr/dolibarr
.
Overview
dolibarr/dolibarr is a modern and easy to use web software to manage your business.
Affected versions of this package are vulnerable to Arbitrary File Upload. Users with the 'Setup documents directories' permission can rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
References
CVSS Scores
version 3.1