packetstormsecurity.com
http://packetstormsecurity.com/files/161955/Dolibarr-ERP-CRM-11.0.4-Bypass-Code-Execution.html CVE-2020-14209
HIGH
Dolibarr Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-14209 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dolibarr/dolibarrBrowse Packagist / dolibarr/dolibarr | GitHub Advisory | Before 11.0.5 · Fixed in 11.0.5 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBDolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)ExploitDB exploitby Andrea GonzalezNot analyzed1 file
References
5github.com
https://github.com/Dolibarr/dolibarr github.comConfirmation
https://github.com/Dolibarr/dolibarr/releases/tag/11.0.5 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-14209 wizlynxgroup.com
https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-012