CVE-2020-14201: Dolibarr

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

Affected products

  • Dolibarr Dolibarr: before 11.0.5 (fixed in 11.0.5)

Published 2020-08-21. Last modified 2026-06-17.