CVE-2020-13240

CVE-2020-13240

The DMS/ECM module in Dolibarr 11.0.4 allows users with the ‘Setup documents directories’ permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

Source: CVE-2020-13240

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다