8.8
CVSSv3

CVE-2020-14209

Published: 02/09/2020 Updated: 30/03/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Dolibarr prior to 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr

Exploits

Dolibarr ERP/CRM version 1104 authenticated file upload restrictions bypass exploit that achieves remote code execution ...