
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-14209 affects Dolibarr ERP/CRM versions before 11.0.5. The vulnerability was discovered by Andrea Gonzalez from wizlynx group and was disclosed on September 25, 2020. This security issue allows low-privilege users to upload files of dangerous types to the system (Wizlynx Advisory).
The vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434) with a CVSS score of 8.8 (High). The issue stems from insufficient file extension filtering where the blacklist mechanism fails to prevent upload of potentially dangerous file types such as .pht, .phar, and .shtml, which can be executed as PHP scripts in default Apache configurations (Wizlynx Advisory).
Successful exploitation of this vulnerability could lead to arbitrary code execution within the context of the vulnerable application. This allows attackers to potentially compromise the integrity, confidentiality, and availability of the system (Wizlynx Advisory).
The vulnerability can be exploited through two main methods: file extension blacklist bypass and .htaccess file upload. The exploitation requires only low privileges and no user interaction, making it relatively easy to exploit in environments where Apache is running with default configurations (Wizlynx Advisory).
The vulnerability was fixed in Dolibarr version 11.0.5. Users should upgrade to this version or later to protect against this security issue (Dolibarr Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."