CVE-2020-13239

The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
References
Link Resource
https://www.dubget.com/stored-xss-via-file-upload.html Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:dolibarr:dolibarr_erp/crm:11.0.4:*:*:*:*:*:*:*

Information

Published : 2020-05-20 03:15

Updated : 2022-11-17 05:21


NVD link : CVE-2020-13239

Mitre link : CVE-2020-13239

Products Affected
No products.
CWE