CVE-2020-14201: Dolibarr
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.
Affected products
- Dolibarr Dolibarr: before 11.0.5 (fixed in 11.0.5)
Published 2020-08-21. Last modified 2026-06-17.