CVE-2020-13240: Incorrect Default Permissions
(updated )
The DMS/ECM module in Dolibarr allows users with the ‘Setup documents directories’ permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe
protection mechanism against XSS.
References
Detect and mitigate CVE-2020-13240 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →