Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

41 – 50 of 121 results


CVE-2020-14201

Medium priority
Vulnerable

Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-14475

Medium priority
Not affected

A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not affected
Show less packages

CVE-2020-14443

Medium priority
Vulnerable

A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-13240

Medium priority
Vulnerable

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-13239

Medium priority
Vulnerable

The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-13094

Negligible priority
Vulnerable

Dolibarr before 11.0.4 allows XSS.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-12669

Medium priority
Vulnerable

core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-11825

Medium priority
Vulnerable

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-11823

Medium priority
Vulnerable

In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2019-19212

Medium priority
Vulnerable

Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages