Arbitrary file upload in dolibarr - CVE-2020-13240
Published: May 28, 2020 / Updated: June 29, 2020
dolibarr
Dolibarr ERP & CRM
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload. A remote authenticated user with "Setup documents directories" permission can rename uploaded files to have insecure file extensions, leading to a malicious file execution on the server.