CVE-2020-14209
PHP vulnerability analysis and mitigation

Overview

CVE-2020-14209 affects Dolibarr ERP/CRM versions before 11.0.5. The vulnerability was discovered by Andrea Gonzalez from wizlynx group and was disclosed on September 25, 2020. This security issue allows low-privilege users to upload files of dangerous types to the system (Wizlynx Advisory).

Technical details

The vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434) with a CVSS score of 8.8 (High). The issue stems from insufficient file extension filtering where the blacklist mechanism fails to prevent upload of potentially dangerous file types such as .pht, .phar, and .shtml, which can be executed as PHP scripts in default Apache configurations (Wizlynx Advisory).

Impact

Successful exploitation of this vulnerability could lead to arbitrary code execution within the context of the vulnerable application. This allows attackers to potentially compromise the integrity, confidentiality, and availability of the system (Wizlynx Advisory).

Exploitability

The vulnerability can be exploited through two main methods: file extension blacklist bypass and .htaccess file upload. The exploitation requires only low privileges and no user interaction, making it relatively easy to exploit in environments where Apache is running with default configurations (Wizlynx Advisory).

Mitigation and workarounds

The vulnerability was fixed in Dolibarr version 11.0.5. Users should upgrade to this version or later to protect against this security issue (Dolibarr Release).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56825HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56829HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56830MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56831MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-49992MEDIUM6.3
  • PHP logoPHP
  • kimai/kimai
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management