The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
References
Link Resource
https://www.dubget.com/stored-xss-via-file-upload.html Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-20T14:57:22

Updated: 2020-05-20T14:57:22

Reserved: 2020-05-20T00:00:00


Link: CVE-2020-13240

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-20T15:15:11.187

Modified: 2022-11-17T17:21:59.260


Link: CVE-2020-13240

JSON object: View

cve-icon Redhat Information

No data.