Vulnerability Details CVE-2020-13239
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 49.0%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2020-13239
-
cpe:2.3:a:dolibarr:dolibarr_erp/crm:11.0.4